<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk App for Enterprise Security 3.3.1: How to change the drilldown offset in a correlated search to last 10 minutes? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-3-3-1-How-to-change-the/m-p/252811#M1831</link>
    <description>&lt;P&gt;I would like to change the drilldown offset in my correlated search to last 10 minutes. Ive tried 10m in first offset box, but not sure what to put in the second offset box. Looks like the "Save" button is validating these fields and putting a "0y" in the second box? Why 0y? Shouldn't I be able to use now? Also, I notice you can use seconds IE 30s. It will automatically be changed to m (minutes)? Is this a correct assumption?&lt;/P&gt;</description>
    <pubDate>Fri, 02 Oct 2015 18:42:34 GMT</pubDate>
    <dc:creator>rroberts</dc:creator>
    <dc:date>2015-10-02T18:42:34Z</dc:date>
    <item>
      <title>Splunk App for Enterprise Security 3.3.1: How to change the drilldown offset in a correlated search to last 10 minutes?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-3-3-1-How-to-change-the/m-p/252811#M1831</link>
      <description>&lt;P&gt;I would like to change the drilldown offset in my correlated search to last 10 minutes. Ive tried 10m in first offset box, but not sure what to put in the second offset box. Looks like the "Save" button is validating these fields and putting a "0y" in the second box? Why 0y? Shouldn't I be able to use now? Also, I notice you can use seconds IE 30s. It will automatically be changed to m (minutes)? Is this a correct assumption?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 18:42:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-3-3-1-How-to-change-the/m-p/252811#M1831</guid>
      <dc:creator>rroberts</dc:creator>
      <dc:date>2015-10-02T18:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security 3.3.1: How to change the drilldown offset in a correlated search to last 10 minutes?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-3-3-1-How-to-change-the/m-p/252812#M1832</link>
      <description>&lt;P&gt;I had the same problem with 3.3.0 so I used "earliest=xxx latest=xxx" in the Drill-down search to work around this.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 14:21:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-3-3-1-How-to-change-the/m-p/252812#M1832</guid>
      <dc:creator>aholzel</dc:creator>
      <dc:date>2015-11-30T14:21:18Z</dc:date>
    </item>
  </channel>
</rss>

