Splunk Search

"In the last 30 Days" VS "Last 30 Days"

jkcouch
Explorer

When I have an inline search on a dashboard where the time range is set to -30d or -30d@d, my last time on my timechart is never consistently yesterday. Sometimes it is yesterday, other times its 5 days ago, depending on the search. How do I fix it so that it shows the null values on every timechart search?

I notice when I do a View Results, the time selection says "in the last 30 days", and when I change it to say "Last 30 days" Because "in the last 30 days" is not available, It works as it should.

Tags (3)
0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

Hard to tell without your data or a screenshot.

  • do you have any timechart options, what is the span ?
  • is it a dashboard, is there any other parameters in the XML that apply ?

If you remark is that the last event of the chart is not always right now, then it may be that you have a condition on the latest condition, or that there is no recent events.

please try to use inline : ealierst=-30d@d latest=now and compare

if you want to see what the timerange list is really, go to : Manager » User interface » Time ranges .

FYI : last_30_days "Last 30 days" earliest=-30d@d latest=now

View solution in original post

yannK
Splunk Employee
Splunk Employee

Hard to tell without your data or a screenshot.

  • do you have any timechart options, what is the span ?
  • is it a dashboard, is there any other parameters in the XML that apply ?

If you remark is that the last event of the chart is not always right now, then it may be that you have a condition on the latest condition, or that there is no recent events.

please try to use inline : ealierst=-30d@d latest=now and compare

if you want to see what the timerange list is really, go to : Manager » User interface » Time ranges .

FYI : last_30_days "Last 30 days" earliest=-30d@d latest=now

yannK
Splunk Employee
Splunk Employee

You can, and hard coded time ranges in the search, will have priority over the external time ranges.

0 Karma

jkcouch
Explorer

That answered my question perfectly. I didnt realize that you were able to set earliest and latest in the search line.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...