Splunk Search

earliest and latest times for each hour of a day ?

rakesh_498115
Motivator

Hi

How can give earliest and latest times for each hour of day of previous day .

i.e first hour , second hour ,third hour and so on

earliest=-0h@d latest=-1h@d
earliest=-1h@d latest=-2h@d
earliest=-2h@d latest=-3h@d

and so on...

but this seems not working ?? any generic way of giving them pls

Tags (1)
0 Karma

gfuente
Motivator

Hello

I think you are looking for this:

earliest=-1d@d+1h latest=-1d@d+2h

This will give you: yesterday between 1 AM and 2 AM, if you change the values of the +1h and +2h you can select any given hour range from yesterday

Regards

Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...