Dashboards & Visualizations

9:37 30m@d

palisetty
Communicator

@gcusello

9:37 -30m@h
Sorry for asking this again. As far as I understand, I will tell you kindly correct me.
@h is current hour, which goes to 9. -30m which is 30 minutes before current hour, so it will be 8:30 - 8:59.


9:37 -30m@d
@d is current day at 0:00 hours. so -30m would be yesterday 23:30 to 23:59.

Tags (1)
0 Karma

pramit46
Contributor

If you run the following search at 09:37 AM:
index=_internal earliest=-1h@h lastest=now, then earliest time will be: 08:00 AM and latest time will be: 09:37 AM

If you run the following search at 09:37 AM:
index=_internal earliest=-1h lastest=now, then earliest time will be: 08:37 AM and latest time will be: 09:37 AM

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...