Dashboards & Visualizations

How to set time modifiers for a saved search to return data for the past one year, but not include the last 7 days?

vrmandadi
Builder

I am doing a saved search which should have a time range for past one year (start date) and end date should ignore the last week from today. Can anyone help me in this?

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

If by "ignore the last week" you mean no events from the last 7 days then try this:

earliest=-1y@d latest=-7d@d
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

If by "ignore the last week" you mean no events from the last 7 days then try this:

earliest=-1y@d latest=-7d@d
---
If this reply helps you, Karma would be appreciated.

ShaneNewman
Motivator

So start date would be earliest=-1y@w latest=-7d@d if I understand you correctly.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Start date would be '-1y@d' (one year ago today) or '-1y@w' (one year ago this week).

End date would be '-7d@d'.

---
If this reply helps you, Karma would be appreciated.

ShaneNewman
Motivator

Thanks for the correction!

0 Karma

vrmandadi
Builder

thanks everyone

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If your problem is solved, please accept the answer.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...