Site Search

How to easily search for events in a specific time period

release date
2018-06-18
last updated
2024-01-11
version
Splunk Enterprise 9.0.4
Overview
You can use the default datetime fields, such as date_hour and date_minute, to search for events within a specific time period.
Reference information
content

Example of use

If you only want to search for events with timestamps between 9:00 and 17:00, add the following condition to your search statement:

date_hour>=9 AND date_hour<=17

It is also possible to search using the above fields after specifying a specific period in advance with the time range picker.

that's all