Splunk Search

What are these time modifiers doing?

splunkfuinator
New Member

I have a search where I want the first search to search the previous week (Sunday to Sunday) and then use the same search to search two weeks ago to the previous week. So, for example, if I ran the search on 11 December 2015, I want the first search to run from 29 November to 6 December, and one search to run 22 November to 29 November. I end up having the first week subtracted from the second week, which is why I have them set up as search / subsearch.

I read the time modifiers documentation (http://docs.splunk.com/Documentation/Splunk/6.2.0/SearchReference/SearchTimeModifiers), but I don't understand the logic behind the modifiers. Can someone please confirm if these are the right modifiers (below) to accomplish this. Additionally, when I run this as a scheduled report, does the time in the search override the time in saved in the Splunk query time selector?

Thanks in advance!

sourcetype="Login" earliest=-1w@w0 latest=@w
...
| appendcols [search sourcetype="Login" earliest=-2w@w1 latest=@w1

0 Karma
1 Solution

woodcock
Esteemed Legend

woodcock
Esteemed Legend

You need the TimeWrap app:

https://splunkbase.splunk.com/app/1645/

splunkfuinator
New Member

That looks awesome, but unfortunately I don't have admin privileges to install anything in Splunk. 😞

0 Karma

woodcock
Esteemed Legend

You can download it and clone the guts; that is what I would do.

0 Karma

splunkfuinator
New Member

Good point. Ty!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...