Dear Splunk users, I am working on an existing dashboard with certain inputs. These inputs are dynamically populated and uses a search query for that. However to filter the events on time, I see a token being used with "where" clause and the xml-tags <earliest> and <latest> are removed. I am just curious what is the default time range does the search pick in this case? The original token uses 2weeks span. I have attached source here.
I would really appreciate if you can provide references to your answers on splunk docs. Thanks and happy splunking 🙂
I am just wondering if the search for this input uses all-time