Do you want Hunk to look at the files that match the search time range? You can probably use regex, for for earliest and latest time specification. Hunk will then search the correct files depending on the time range you search. Please see the following document for more details.
http://docs.splunk.com/Documentation/Hunk/latest/Hunk/SetupvirtualindexesforarchivedHadoopfiles
In your case, you can probably have something like the following.
[hadoop]
vix.provider = <provider_name>
vix.input.1.path = har:///<path_to_archive_file>/<archive_file>.har/...
vix.input.1.accept = \.gz$
vix.input.1.et.regex = /home/myindex/data/(\d+)/(\d+)/(\d+)/
vix.input.1.et.format = yyyyMMdd
vix.input.1.et.offset = 0
vix.input.1.lt.regex = /home/myindex/data/(\d+)/(\d+)/(\d+)/
vix.input.1.lt.format = yyyyMMdd
vix.input.1.lt.offset = 86400
... View more