Hi MuS,
Example 1: search sourcetype=".... earliest=-7d@d latest=@d ( Last Week )
Example 2: search sourcetype=".....earliest=-1d@d latest=@d ( Yesterday )
Simple:@d will truncate data till midnight
This example show last week and yesterday data ending by midnight.
Thanks,
Hi MuS,
Example 1: search sourcetype=".... earliest=-7d@d latest=@d ( Last Week )
Example 2: search sourcetype=".....earliest=-1d@d latest=@d ( Yesterday )
Simple:@d will truncate data till midnight
This example show last week and yesterday data ending by midnight.
Thanks,
will example 1 show mon-sun of last week if run on a wednesday? Or does it have to be run on a monday?
Hi royimad
that would be latest=-1d@d
to be used in your search.
You can find time modifiers here or in the UI select the time range picker - custom time and in the next screen select Advanced search language
and start with your test. The nice thing in the UI is, that the time modifiers like -1d@d
gets translated into human readable time.
hope that helps....
cheers, MuS