Reporting

can I get the earliest and latest time of custom time and/or the scheduled search in my search?

marcokrueger
Path Finder

huhu dear community,
is there a possibility to get the values from

  1. the timerange of the custom time...?
  2. the timerange of a scheduled search?

Background: I have s search with a subsearch, where the subsearch needs events of a different index with a time-offset. I think I need a variable like my dummies global_earliest and global_latest
index=ABC | append [ index=DEF earliest=global_earliest-3600 lastest=global_latest-3600 ] | ...

thank you
Marco 🙂

Tags (3)
0 Karma

Ayn
Legend
0 Karma

marcokrueger
Path Finder

I thought the addinfo is only availaible after the search, is this right?
How can I use the addinfo-result in the subsearch? Can you please give me an example?

Best regards
Marco

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...