Hi All,
Can anyone help me on the time modifiers ... for giving the earliest and latest for yesterday morning 5 am to today morning 5 am.
earliest=-1d@5h latest=-0d@5h but this doesnt work
thanks.
Hi rakesh_498115,
how about:
earliest=10/07/2014:05:00:00 latest=10/08/2014:05:00:00
if run today. See docs for more details http://docs.splunk.com/Documentation/Splunk/6.1.4/Search/Specifytimemodifiersinyoursearch
cheers, MuS
I was looking for generic timestamp Mus. Thanks for ur reply.. 🙂
Hi,
try earliest=-1d@d+5h and latest=@d+5h
Greetings
Tom
Great tom.. missed this + sign.. thanks 🙂