Dashboards & Visualizations

How to set time modifiers for a saved search to return data for the past one year, but not include the last 7 days?

vrmandadi
Builder

I am doing a saved search which should have a time range for past one year (start date) and end date should ignore the last week from today. Can anyone help me in this?

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

If by "ignore the last week" you mean no events from the last 7 days then try this:

earliest=-1y@d latest=-7d@d
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

If by "ignore the last week" you mean no events from the last 7 days then try this:

earliest=-1y@d latest=-7d@d
---
If this reply helps you, Karma would be appreciated.

ShaneNewman
Motivator

So start date would be earliest=-1y@w latest=-7d@d if I understand you correctly.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Start date would be '-1y@d' (one year ago today) or '-1y@w' (one year ago this week).

End date would be '-7d@d'.

---
If this reply helps you, Karma would be appreciated.

ShaneNewman
Motivator

Thanks for the correction!

0 Karma

vrmandadi
Builder

thanks everyone

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If your problem is solved, please accept the answer.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...