Splunk Search

"In the last 30 Days" VS "Last 30 Days"

jkcouch
Explorer

When I have an inline search on a dashboard where the time range is set to -30d or -30d@d, my last time on my timechart is never consistently yesterday. Sometimes it is yesterday, other times its 5 days ago, depending on the search. How do I fix it so that it shows the null values on every timechart search?

I notice when I do a View Results, the time selection says "in the last 30 days", and when I change it to say "Last 30 days" Because "in the last 30 days" is not available, It works as it should.

Tags (3)
0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

Hard to tell without your data or a screenshot.

  • do you have any timechart options, what is the span ?
  • is it a dashboard, is there any other parameters in the XML that apply ?

If you remark is that the last event of the chart is not always right now, then it may be that you have a condition on the latest condition, or that there is no recent events.

please try to use inline : ealierst=-30d@d latest=now and compare

if you want to see what the timerange list is really, go to : Manager » User interface » Time ranges .

FYI : last_30_days "Last 30 days" earliest=-30d@d latest=now

View solution in original post

yannK
Splunk Employee
Splunk Employee

Hard to tell without your data or a screenshot.

  • do you have any timechart options, what is the span ?
  • is it a dashboard, is there any other parameters in the XML that apply ?

If you remark is that the last event of the chart is not always right now, then it may be that you have a condition on the latest condition, or that there is no recent events.

please try to use inline : ealierst=-30d@d latest=now and compare

if you want to see what the timerange list is really, go to : Manager » User interface » Time ranges .

FYI : last_30_days "Last 30 days" earliest=-30d@d latest=now

yannK
Splunk Employee
Splunk Employee

You can, and hard coded time ranges in the search, will have priority over the external time ranges.

0 Karma

jkcouch
Explorer

That answered my question perfectly. I didnt realize that you were able to set earliest and latest in the search line.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...