I'm trying to configure a search Time Window for my Splunk roles. I've read the documentation but can't find instruction on what to set for the srchTimeWin attribute. The spec file indicates:
* Maximum time span of a search.
The value should be an number indicating the number of seconds that a search query may span, e.g., 60 for one minutes, 86400 for one day.
View solution in original post