LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

What does error earliest=-1d@d latest=-1h@h mean in Splunk, and how does "snapping" work?

Events containing "error" from yesterday at midnight until the start of the current hour: -1d@d means go back one day, then round down to the start of that day; -1h@h means go back one hour, then round down to the full hour.

Timeline from Tuesday to Wednesday: now 14:37, -1d snaps to Tuesday 00:00, -1h snaps to 13:00; the searched window is Tuesday 00:00 to Wednesday 13:00

* Go back, then round down: the window is whole days and hours, not rolling. *

Relative time modifiers have the form [+|-]<integer><unit>@<snap_unit>:

  • Units: s seconds, m minutes, h hours, d days, w weeks, mon months, q quarters, y years. The integer defaults to 1, so m equals 1m.
  • Snapping (@) rounds down to the start of the given unit. At 11:59, @h snaps to 11:00, not 12:00.
  • Weekdays: @w0 snaps to Sunday, @w1 to Monday, and so on.

Worked example, if it is now 14:37 on Wednesday:

Modifier Resolves to
-1d@d Tuesday 00:00
-1h@h Wednesday 13:00
@w1 Monday 00:00 of this week

Snapping makes reports reproducible: "yesterday" means the whole calendar day regardless of when the search runs, instead of "the last 24 hours from right now".

Go deeper:

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026