Closed DavidJBianco closed 4 years ago
The SplunkDF.search() code converts the datetime to a Splunk search parameter incorrectly. Instead of calling datetime.isoformat() it should instead call datetime.strftime("%m/%d/%Y:%H:%M:%S").
Unable to reproduce this anymore with the latest Splunk 8.
Describe the bug The start_time argument is supposed to accept a Python datetime object, but when searches using that feature return quickly with no data. Searches for the same timeframe using the alternative SPL syntax (e.g., start_time="-15m@m") take significantly longer and do return relevant data.
To Reproduce Here's a code fragment that demonstrates the problem:
Expected behavior Expected a DataFrame with search results
Additional context