Splunk® Enterprise

Search Manual

Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Select time ranges to apply to your search

Use the time range picker to set time boundaries on your searches. You can restrict the search to Preset time ranges, custom Relative time ranges, and custom Real-time time ranges. You can also specify a Date Range, a Date & Time Range, and use more advanced options for specifying the time ranges for a search.

Note: If you are located in a different timezone, time-based searches use the timestamp of the event from the instance that indexed the data.

Select from a list of Preset time ranges

Out of the box, the time range picker includes many time ranges options that are already defined in the configuration file, times.conf. You can select from a list of Real-time windows, Relative time ranges, and search over All Time.

Tutorials timerangepicker presets.png

Define custom Relative time ranges

The custom Relative time range option enables you to specify a time range for your search relative to Now or "Beginning of the current second".

Tutorials timerange custom relative.png

The preview box below the text field will update to the time range you're setting.

Read more about Relative time ranges in the next topic, "Specify time modifiers in your search".

Define custom Real-time time ranges

The custom Real-time option enables you to specify the start time for your real-time time range window.

Search custom realtime range.png

Read more about real-time time ranges in the topic "Specify real-time time range windows in your search".

Define custom Date ranges

Use the custom Date Range option to specify calendar dates in your search. You can choose among options to return events: Between a beginning and end date, Before a date, and Since a date.

For these fields, you can type the date into the text box or select the date from a calendar:

Search timerange date between.png

Define custom Date & Time ranges

Use the custom Date & Time Range option to specify calendar dates and times for the beginning and ending of your search.

Tutorials timerange datetime.png

You can type the date into the text box or select the date from a calendar.

Use Advanced time range options

Use the Advanced option to specify the earliest and latest search times. You can write the times in Unix (epoch) time or relative time notation. The epoch time value you enter is converted to local time. This timestamp is displayed under the text field so that you can verify your entry.

Search advanced timerange.png

Customize the time ranges you can select

Splunk now ships with more built-in time ranges. Splunk administrators can also customize the set of time ranges that you view and select from the drop down menu when you search. For more information about configuring these new time ranges, see the times.conf reference in the Admin Manual.

Change the default selected time range

If you want the time range picker to read something other than "All time" by default, you can change this to another time range. It can be set for a specific user, by setting that user's ui-prefs, or for an entire app. To do this, edit or create the ui-prefs.conf to specify a new default time range.

The following example changes the default time range from All Time to Today within the Search app.

dispatch.earliest_time = @d
dispatch.latest_time = now

If you want to change this default for another view, the stanza name needs to match the dashboard ID for that view. These parameter values are defined using relative time modifiers, which you can read more about in the topic "Specify time modifiers in your search".

You would create this in $SPLUNK_HOME/etc/apps/search/local/ui-prefs.conf if you wanted to add it to the search app, only. If you want to specify the global default, add these paramters to $SPLUNK_HOME/etc/system/local/ui-prefs.conf. For more information, refer to the ui-prefs.conf reference in the Admin Manual.

About time ranges in search
Specify time modifiers in your search

This documentation applies to the following versions of Splunk® Enterprise: 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15, 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.1.14

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters