About the time range picker
Use the time range picker, which is to the right of the search bar, to set time boundaries on your searches.
You can restrict the search to Preset time ranges, custom Relative time ranges, and custom Real-time ranges or specify a Date Range or a Date & Time Range.
For this tutorial, you will select from the time range Presets and define custom Relative time ranges.
Time range presets
The time range picker Presets are a set of time ranges that are defined in Splunk Enterprise out-of-the-box.
By default, the time range for a search is set to All time. Usually, when you run a search over large volumes of data, you see faster results if you run the search over a smaller time period. To change the default time range for your searches, see "Change the default selected time range" in the Search manual.
When troubleshooting an issue where you know the ballpark range for when the issue occurred, narrow the time range of the search to that time period. For example, if you are investigating an incident that occurred yesterday, you select Yesterday or Last 24 hours. If you're investigating an incident that occurred 10 minutes ago, you select Last 15 minutes or Last 60 minutes.
Custom time ranges
If one of the Presets is not what you want, you can define a custom time range, such as a Relative time range or a Date & Time Range.
If you are interested in events in the last two hours, you can specify it with the Relative time range option.
For example, you can specify the earliest time to read "2 Hours Ago" and latest time to be either "now" or "Beginning of the current hour".
You can narrow down more precisely into the time range when you specify a Date & Time Range.
For example, if you are interested in events that occurred on September 30th at 8:42 PM. You can specify the earliest time to be 09/30/2013 08:40:00.000 and the latest time to be 09/30/2013 08:45:00.000.
Continue reading to learn about search actions and search modes.
About the Search dashboard
About search actions and modes
This documentation applies to the following versions of Splunk® Enterprise: 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12