Splunk Search

How do I search with a self adjusting time?

fmerrow
New Member

So on the GUI I have been looking at the various time pickers . . . specifically "Date & Time" and "Advanced".

I see advanced in particular can do limited arithmetic (@d-1m), etc.

Basically, what I am hoping for, is for the user to cut a date/time out of a log, then come to say "Advanced" and do the following:

In Earliest have something prepopulated like lastest-2m and in Latest paste the copied value.

Now I realize the same could be accomplished with "Date&Time", except the date needs to be pasted twice and then earliest needs to be played with by hand.

I am hoping to get this down to a single paste and no hand editing . . . just paste and search.

Is that possible?

Frank

0 Karma

woodcock
Esteemed Legend
0 Karma

fmerrow
New Member

Interesting . . . I'll check it out. Thank you.

0 Karma
Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...