Reporting

Adjusting earliest/latest for both main search and sub-search

yyossef
Explorer

Hi,

I am encountering difficulty running different time range for main search and sub-search at the same time, while the time string is been received (ltime) from a savesearch.

attached are the savesearch i am running, and also the report wich is run by the savesearch.

savedsearch:
| savedsearch ltime="09/09/2017 22:00:00"

reportname:
index=GroupA latest=$ltime$ earliest=$ltime$-30m [ search index=GroupB earliest=$ltime$-7d latest=$ltime$ | table IP ] | stats latest(STATE) by IP

I would like to receive the latest time from a savedsearch and base on that, calculate the earliest/last parameter for both main search and sub-search.

I would appreciate Any advice , thanks!

aholzer
Motivator

Modifying time tokens is a little tricky, here's a link to another Splunk answers question that has a working solution to your problem.

Hope this helps

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...