Splunk® Enterprise

Search Tutorial

Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

About the time range picker

Use the time range picker, which is to the right of the search bar, to set time boundaries on your searches.

6.1 tutorial timerange picker.png

You can restrict the search to Preset time ranges, custom Relative time ranges, and custom Real-time ranges or specify a Date Range or a Date & Time Range.

For this tutorial, you will select from the time range Presets and define custom Relative time ranges.

Time range presets

The time range picker Presets are a set of time ranges that are defined in Splunk Enterprise out-of-the-box.

6.1 tutorial timerange presets.png

By default, the time range for a search is set to All time. Usually, when you run a search over large volumes of data, you see faster results if you run the search over a smaller time period. To change the default time range for your searches, see "Change the default selected time range" in the Search manual.

When troubleshooting an issue where you know the ballpark range for when the issue occurred, narrow the time range of the search to that time period. For example, if you are investigating an incident that occurred yesterday, you select Yesterday or Last 24 hours. If you're investigating an incident that occurred 10 minutes ago, you select Last 15 minutes or Last 60 minutes.

Custom time ranges

If one of the Presets is not what you want, you can define a custom time range, such as a Relative time range or a Date & Time Range.

If you are interested in events in the last two hours, you can specify it with the Relative time range option.

6.1 tutorial timerange relative.png

For example, you can specify the earliest time to read "2 Hours Ago" and latest time to be either "now" or "Beginning of the current hour".

You can narrow down more precisely into the time range when you specify a Date & Time Range.

6.1 tutorial timerange datetime.png

For example, if you are interested in events that occurred on September 30th at 8:42 PM. You can specify the earliest time to be 09/30/2013 08:40:00.000 and the latest time to be 09/30/2013 08:45:00.000.

Next steps

Continue reading to learn about search actions and search modes.

Last modified on 06 October, 2014
About the Search dashboard
About search actions and modes

This documentation applies to the following versions of Splunk® Enterprise: 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters