Splunk Search

Where _time > 3/22/2018

griffinpair
Path Finder

I have events that only time stamp is the Splunk generated _time and I only need to return events after a certain date, 3/22/2018. Simply adding "Where _time > 3/22/2018" does not work and I have attempted converting _time and comparing against that to no avail.

Any suggestions?

jihape
Path Finder

If _time is the time you want to use for searches, using the time picker should work just fine.

skoelpin
SplunkTrust
SplunkTrust

Try this

index=...
| eval epoch=strptime("YOUR_TIME_FIELD", "%m/%d/%Y") 
| where epoch >1521748648
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...