Hello,
I'm trying to complete a simple request such as :
earliest="04/12/2017:08:24:24" lastest="04/12/2017:09:25:24" index=xxx
But I have no results from this search.
I've successfully tried to use just earliest field
earliest="04/12/2017:08:24:24" index=xxx
But with lastest field, I got no results once again:
lastest="04/12/2017:09:25:24" index=xxx
Is it something wrong with lastest field ?
Thanks,
"Lastest" is not a Splunk keyword. Use "latest".
Indeed, thanks for notification.
But even with latest, I got no events ....
When you leave out latest
are the event times before 04/12/2017:09:25:24?