While querying in Splunk, we have the Time range selection drop-down on the right-hand side.
When selecting the range If find myself copying and pasting 4 times usually.
- From date
- From time
- To date
- To time
I have to do this several times daily - I find it super annoying!
My question(s):
- Is there a way to customize the Splunk range selector?
- Or Is there a more effective way to do such queries?
A different approach is to ignore the date range selector and use Date range queries.
The following can be added to a query.
See the documentation for more information.
Some handy examples from the documentation
To search for data from now and go back in time 5 minutes
To search for data between 2 and 4 hours ago
To search for data using an exact date range, such as from October 15 at 8 PM to October 22 at 8 PM
Or with specify dates like
To search for data from the beginning of today (12 AM or midnight)
The @ symbol is referred to as the snap to and d is the time unit.
Finally, To search for data from the beginning of today (12 AM or midnight) and apply a time offset of -2h