Hi
I am trying to generate a report which i want to run at 2:30PM on 3 days a week only for the time range choosen as 1:25 PM to 1:30 PM how to pass the values earliest and latest in this case ?
is it like i have to convert the date and time to epoch time first and then pass it to earliest and latest or how to achieve in a simpler way?
@surekhasplunk , Can you try including time modifiers in earliest and latest like below-
index=<yourindexname> earliest=-65m latest=-1h
index=yours your_main_search_string
[| makeresults
| eval earliest=strftime(_time,"%m/%d/%Y").":13:25:00"
| eval latest=strftime(_time,"%m/%d/%Y").":13:30:00"
| format]
use sub search to send earliest
and latest
reference: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/SearchTimeModifiers
@surekhasplunk , Can you try including time modifiers in earliest and latest like below-
index=<yourindexname> earliest=-65m latest=-1h