Am currently new to Splunk and I'm facing an issue regarding the time range picker pulling up results that are inaccurate.
As I have select the last 24 hours options for the time range picker, the results that are displayed were only till a certain timing and not the full 24 hours duration.
I have attached a screenshot of the data captured as well as the time I have run the search. As seen in the screenshot, the last data captured was 5.52pm 28/3/19, while my last indexed data was at 3am on 29/3/19. Could anyone help me out on this? There seems to be a 8 hour difference in my time range picker when filtering the data. Thanks!
imgur.com/a/5hYT6Fb ( Was unable to provide the link as I don't have enough points..)
@synastraa you should be able to add image using the
image <img> button or shortcut
Ctrl+G on Splunk Answers.