<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Differences in splunk documentation in Security</title>
    <link>https://community.splunk.com/t5/Security/Differences-in-splunk-documentation/m-p/128787#M14541</link>
    <description>&lt;P&gt;I tried with unit as 'm' and it seems to be working&lt;/P&gt;</description>
    <pubDate>Fri, 11 Apr 2014 22:27:20 GMT</pubDate>
    <dc:creator>strive</dc:creator>
    <dc:date>2014-04-11T22:27:20Z</dc:date>
    <item>
      <title>Differences in splunk documentation</title>
      <link>https://community.splunk.com/t5/Security/Differences-in-splunk-documentation/m-p/128785#M14539</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We use splunk's scripted authentication mechanism in our product. Initially we set the cachetiming to 1s. Since its adding lot of load on the system, we wanted to increase the polling time intervals to 10 min. While going through the documentation i noticed that for setting time in minutes its given as &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;min(s) in &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.3/Admin/Authenticationconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.0.3/Admin/Authenticationconf&lt;/A&gt;  &lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;m in &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.2/Security/Editauthenticationconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.2/Security/Editauthenticationconf&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Which one is right?&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;
Strive&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 12:10:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Differences-in-splunk-documentation/m-p/128785#M14539</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-04-11T12:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: Differences in splunk documentation</title>
      <link>https://community.splunk.com/t5/Security/Differences-in-splunk-documentation/m-p/128786#M14540</link>
      <description>&lt;P&gt;These searches are equivalent:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal earliest=-15m latest=now
index=_internal earliest=-15min latest=now
index=_internal earliest=-15mins latest=now
index=_internal earliest=-15minute latest=now
index=_internal earliest=-15minutes latest=now
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So I assume the configuration might work the same in accepting all five ways of expression the minute unit.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 12:34:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Differences-in-splunk-documentation/m-p/128786#M14540</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-11T12:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: Differences in splunk documentation</title>
      <link>https://community.splunk.com/t5/Security/Differences-in-splunk-documentation/m-p/128787#M14541</link>
      <description>&lt;P&gt;I tried with unit as 'm' and it seems to be working&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 22:27:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Differences-in-splunk-documentation/m-p/128787#M14541</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-04-11T22:27:20Z</dc:date>
    </item>
  </channel>
</rss>

