Splunk Search

Where _time > 3/22/2018

griffinpair
Path Finder

I have events that only time stamp is the Splunk generated _time and I only need to return events after a certain date, 3/22/2018. Simply adding "Where _time > 3/22/2018" does not work and I have attempted converting _time and comparing against that to no avail.

Any suggestions?

jihape
Path Finder

If _time is the time you want to use for searches, using the time picker should work just fine.

skoelpin
SplunkTrust
SplunkTrust

Try this

index=...
| eval epoch=strptime("YOUR_TIME_FIELD", "%m/%d/%Y") 
| where epoch >1521748648
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...