How can I have a start time on my search, so that it starts every time reflecting the current time. I want to display a line chart/graph showing the beginning of my search as it progresses over time. My command so far is this......

source="/var/log/scenario1.log" | timechart span=5s max(host_bandwidth) by host

Re: Start time search in splunk

under the section 'Specify real-time time range windows':

The syntax for real-time time modifers is:


You can find more information about the syntax for time modifiers in the topic, Change the time range of your search.

