Splunk Search

show last week values Mon-Sun and NOT Sun-Sat using earliest and latest

HattrickNZ
Motivator

How do I use earliest and latest to show last week Mon - Sun inclusive.

I have tried this earliest=-1w@w latest = @w but this is giving me Sun to Sat inclusive.

I would like to do it using this type of method earliest=-1w@w latest = @w

Tags (3)
0 Karma

MuS
Legend

Hi HattrickNZ,

you can use something like this instead:

w0 = Sunday w1 = Monday etc...

example: earliest=@w0 
 Searches from the current time to the previous Sun

Hope that helps ...

cheers, MuS

HattrickNZ
Motivator

tks jsut confirming that

earliest=-1w@w1 latest = @w1 will give me last week values for Mon - Sun

hmm, I can't seem to upload a picture file.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...