Dashboards & Visualizations

Specific day to Specific day in panel

tom_rook
Engager

I'm trying to display results within my panels on my dashboard for the previous week Sunday at 12am to Sat at 11:59:59pm. I've tried using -w0 to -w6, but it keeps throwing date range error. And I tried using -w, but that does not appear to give me the previous week, and if does could someone clarify if it giving me the range I'm looking for?

TIA for the help!

0 Karma
1 Solution

jtrucks
Splunk Employee
Splunk Employee

Try:

-1week@week to -0week@week

OR

-1w@w to -0w@w

For more info on time abbreviations see:

http://docs.splunk.com/Documentation/Splunk/5.0.3/SearchReference/SearchTimeModifiers

--
Jesse Trucks
Minister of Magic

View solution in original post

jtrucks
Splunk Employee
Splunk Employee

Try:

-1week@week to -0week@week

OR

-1w@w to -0w@w

For more info on time abbreviations see:

http://docs.splunk.com/Documentation/Splunk/5.0.3/SearchReference/SearchTimeModifiers

--
Jesse Trucks
Minister of Magic

tom_rook
Engager

Thanks for the quick response, and I appreciate the help. That page is much more helpful than the one I was looking at
http://docs.splunk.com/Documentation/Splunk/5.0.2/Search/Specifytimemodifiersinyoursearch

Thanks for the quick and accurate response.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...