I would like to read log data by the time the log was ingested, not the time the log was written. For example, give me logs ingested by Splunk in the last 30 seconds. This is almost like a real-time ingestion, except I'm not looking at the log entry time.
See if this gives you what you're looking for
See if this gives you what you're looking for
I can't get to the link provided.
Thanks
That's it! Thank you.