Splunk Search

"In the last 30 Days" VS "Last 30 Days"

jkcouch
Explorer

When I have an inline search on a dashboard where the time range is set to -30d or -30d@d, my last time on my timechart is never consistently yesterday. Sometimes it is yesterday, other times its 5 days ago, depending on the search. How do I fix it so that it shows the null values on every timechart search?

I notice when I do a View Results, the time selection says "in the last 30 days", and when I change it to say "Last 30 days" Because "in the last 30 days" is not available, It works as it should.

Tags (3)
0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

Hard to tell without your data or a screenshot.

  • do you have any timechart options, what is the span ?
  • is it a dashboard, is there any other parameters in the XML that apply ?

If you remark is that the last event of the chart is not always right now, then it may be that you have a condition on the latest condition, or that there is no recent events.

please try to use inline : ealierst=-30d@d latest=now and compare

if you want to see what the timerange list is really, go to : Manager » User interface » Time ranges .

FYI : last_30_days "Last 30 days" earliest=-30d@d latest=now

View solution in original post

yannK
Splunk Employee
Splunk Employee

Hard to tell without your data or a screenshot.

  • do you have any timechart options, what is the span ?
  • is it a dashboard, is there any other parameters in the XML that apply ?

If you remark is that the last event of the chart is not always right now, then it may be that you have a condition on the latest condition, or that there is no recent events.

please try to use inline : ealierst=-30d@d latest=now and compare

if you want to see what the timerange list is really, go to : Manager » User interface » Time ranges .

FYI : last_30_days "Last 30 days" earliest=-30d@d latest=now

yannK
Splunk Employee
Splunk Employee

You can, and hard coded time ranges in the search, will have priority over the external time ranges.

0 Karma

jkcouch
Explorer

That answered my question perfectly. I didnt realize that you were able to set earliest and latest in the search line.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...