I set the "Restrict search time range" in the role configuration to 3 days, now for the event index, Splunk only returns 3 days of data, base on the latest time user selected. but for metric search(mstats), it still returns data for a longer period(base on user's selection), wonder if the restriction only works for event index? or is there any other way I could restrict the search window for metric search?
attached the solution which worked for the event index https://community.splunk.com/t5/Dashboards-Visualizations/Limit-how-far-back-you-can-retrieve-data-r...