All Apps and Add-ons

Hi, Splunk defaults to 1 hour per column, how can I change that to 1 min per column to get a more detailed view?

New Member

Hi, Splunk defaults to 1 hour per column, how can I change that to 1 min per column to get a more detailed view?

Tags (1)
0 Karma

Motivator

Your default will be based on the time frame that search is running over. If you're charting you can alter the span using span=1m

0 Karma