This documentation does not apply to the most recent version of Splunk.
This documentation applies to the following versions of Splunk: 3.2 , 3.2.1 , 3.2.2 , 3.2.3 , 3.2.4 , 3.2.5 , 3.2.6 , 3.3 , 3.3.1 , 3.3.2 , 3.3.3 , 3.3.4 , 3.4 , 3.4.1 , 3.4.2 , 3.4.3 , 3.4.5 , 3.4.6 , 3.4.8 , 3.4.9 , 3.4.10 , 3.4.11 , 3.4.12 , 3.4.13
Use modifiers to narrow your search results.
You can use modifiers anywhere within a Splunk command: before, after, or in between keywords and logical expressions.
Some modifiers let you use wildcards, regular expressions, and comparison operations to specify values to match.
Most modifiers don't have default values.
| Time modifiers = | daysago, enddaysago, endhoursago, endminutesago, endmonthsago, endtime, endtimeeu, hoursago, minutesago, monthsago, searchtimespandays, searchtimespanhours, searchtimespanminutes, searchtimespanmonths, startdaysago, starthoursago, startminutesago, startmonthsago, starttime, starttimeeu, timeformat | |
| Search modifiers = | eventtypetag, hosttag, savedsearch, tag |
Express modifiers in two ways:
Splunk Modifier expressions have a few precedence rules:
search command before, after, or in between keywords and logical expressions.
daysago, hoursago, or minutesago.