Splunk Search

How to set earliest and latest to run a search for an alert from 7am to 7pm?

sravankaripe
Communicator

I want to run a search for an alert from 7am to 7pm. Please help me with earliest and latest values

earliest=?
latest=?
0 Karma
1 Solution

cmerriman
Super Champion
earliest=@d+7h latest=@d+19h

i think that would do it.

View solution in original post

cmerriman
Super Champion
earliest=@d+7h latest=@d+19h

i think that would do it.

Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...