<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Defining a Real time search window in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Defining-a-Real-time-search-window/m-p/99115#M25586</link>
    <description>&lt;P&gt;Hi oreni&lt;/P&gt;

&lt;P&gt;did you enable the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/User/RealtimeSearch?r=searchtip#Specify_real-time_time_range_windows"&gt;Real-time backfill&lt;/A&gt; in limits.conf?&lt;/P&gt;

&lt;P&gt;cheers&lt;/P&gt;</description>
    <pubDate>Thu, 27 Oct 2011 14:18:14 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2011-10-27T14:18:14Z</dc:date>
    <item>
      <title>Defining a Real time search window</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Defining-a-Real-time-search-window/m-p/99114#M25585</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I would like to set a real time search which counts events occurred starting from the beginning of the day (12am) until current time. &lt;/P&gt;

&lt;P&gt;Using the convention of "earliest=-0d@d latest=rt" yielded an error. &lt;/P&gt;

&lt;P&gt;Any ideas on how to define such window in real time search ?  &lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2011 14:01:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Defining-a-Real-time-search-window/m-p/99114#M25585</guid>
      <dc:creator>oreni</dc:creator>
      <dc:date>2011-10-27T14:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: Defining a Real time search window</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Defining-a-Real-time-search-window/m-p/99115#M25586</link>
      <description>&lt;P&gt;Hi oreni&lt;/P&gt;

&lt;P&gt;did you enable the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/User/RealtimeSearch?r=searchtip#Specify_real-time_time_range_windows"&gt;Real-time backfill&lt;/A&gt; in limits.conf?&lt;/P&gt;

&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2011 14:18:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Defining-a-Real-time-search-window/m-p/99115#M25586</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2011-10-27T14:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: Defining a Real time search window</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Defining-a-Real-time-search-window/m-p/99116#M25587</link>
      <description>&lt;P&gt;Yes, I've set this flag to true and still there was no change.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2011 14:22:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Defining-a-Real-time-search-window/m-p/99116#M25587</guid>
      <dc:creator>oreni</dc:creator>
      <dc:date>2011-10-27T14:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: Defining a Real time search window</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Defining-a-Real-time-search-window/m-p/99117#M25588</link>
      <description>&lt;P&gt;Hi oreni&lt;/P&gt;

&lt;P&gt;The 'rt' values are not designed to be used within the search language. They are configuration values that can be used inside times.conf (to add predefined options to the Time Range Picker), in the saved search dialog or if you were directly using the REST API to access the splunk backend search engine.&lt;/P&gt;

&lt;P&gt;I just tested it and this entry in times.conf works fine in 4.1.8:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[rt-yesterday]
label = Real-Time Yesterday
earliest_time = rt-1d@d
latest_time = rt
order = 10
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2011 12:20:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Defining-a-Real-time-search-window/m-p/99117#M25588</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2011-10-28T12:20:47Z</dc:date>
    </item>
  </channel>
</rss>

