<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: time start and time end in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/time-start-and-time-end/m-p/17287#M2173</link>
    <description>&lt;P&gt;What sourcetype are you searching?&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jul 2010 21:10:15 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2010-07-13T21:10:15Z</dc:date>
    <item>
      <title>time start and time end</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/time-start-and-time-end/m-p/17285#M2171</link>
      <description>&lt;P&gt;im doing a username search and i want two fields in my results table to be the time the user sarted the connection and also when they disconnected the session to the network. What is this information classified as, and wat field would it be called?&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;

&lt;P&gt;happy splunking&lt;/P&gt;

&lt;P&gt;blake&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2010 19:07:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/time-start-and-time-end/m-p/17285#M2171</guid>
      <dc:creator>riderofyamaha</dc:creator>
      <dc:date>2010-07-13T19:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: time start and time end</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/time-start-and-time-end/m-p/17286#M2172</link>
      <description>&lt;P&gt;so people will click minus one but cant answer a simple question. This site really is disappointing me&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2010 20:55:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/time-start-and-time-end/m-p/17286#M2172</guid>
      <dc:creator>riderofyamaha</dc:creator>
      <dc:date>2010-07-13T20:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: time start and time end</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/time-start-and-time-end/m-p/17287#M2173</link>
      <description>&lt;P&gt;What sourcetype are you searching?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2010 21:10:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/time-start-and-time-end/m-p/17287#M2173</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2010-07-13T21:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: time start and time end</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/time-start-and-time-end/m-p/17288#M2174</link>
      <description>&lt;P&gt;The problem is there is not enough information to help you with your question.  What are type of system are they connecting to? Unix, Windows... &lt;/P&gt;

&lt;P&gt;Also have you had a chance to go through the knowledgebase? &lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/latest/User/HowSearchCommandsWork"&gt;http://www.splunk.com/base/Documentation/latest/User/HowSearchCommandsWork&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/4.1.3/Knowledge/Aboutfields"&gt;http://www.splunk.com/base/Documentation/4.1.3/Knowledge/Aboutfields&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/latest/User/SearchExamples"&gt;http://www.splunk.com/base/Documentation/latest/User/SearchExamples&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Here a few that may help.  &lt;/P&gt;

&lt;P&gt;Travis.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2010 21:41:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/time-start-and-time-end/m-p/17288#M2174</guid>
      <dc:creator>thall79</dc:creator>
      <dc:date>2010-07-13T21:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: time start and time end</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/time-start-and-time-end/m-p/17289#M2175</link>
      <description>&lt;P&gt;im searching sys logs, on a windows system....ive also read through the documentation text with no success so far. I want to show a connection start and end time in a form search results field&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2010 22:05:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/time-start-and-time-end/m-p/17289#M2175</guid>
      <dc:creator>riderofyamaha</dc:creator>
      <dc:date>2010-07-13T22:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: time start and time end</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/time-start-and-time-end/m-p/17290#M2176</link>
      <description>&lt;P&gt;???????????????&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2010 22:15:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/time-start-and-time-end/m-p/17290#M2176</guid>
      <dc:creator>riderofyamaha</dc:creator>
      <dc:date>2010-07-14T22:15:58Z</dc:date>
    </item>
  </channel>
</rss>

