Relative lookbacks
You will learn relative time tokens and absolute presets.
Relative tokens
Used as Period on Query and Lookback on relative views.
| UI label | Token |
|---|---|
| Last 5 minutes | 5m |
| Last 15 minutes | 15m |
| Last 30 minutes | 30m |
| Last hour | 1h |
| Last 3 hours | 3h |
| Last 12 hours | 12h |
| Last 24 hours | 24h |
| Last 3 days | 3d |
| Last 7 days | 7d |
| Last 14 days | 14d |
| Last 30 days | 30d |
API/MCP requests send relative with the token (for example "24h").
Optional time_basis (ingested_at default, or event_time) chooses which
clock the lookback applies to. Receipt time is when Cordo stored the event;
event time is the producer timestamp derived at ingest.
Absolute / fixed ranges
On Query, choose Fixed and set from / to (ISO UTC).
On absolute views, common presets include Today, Yesterday, This week, Last week, This month, Last month, plus Custom datetime pickers.
Live
Views can use time mode live to tail matching events. Live is not a relative lookback token — it is a separate mode.