Installation

What time format do I use when setting srchTimeWin (in authorize.conf)?

the_wolverine
Champion

I'm trying to configure a search Time Window for my Splunk roles. I've read the documentation but can't find instruction on what to set for the srchTimeWin attribute. The spec file indicates:

srchTimeWin = * Maximum time span of a search.

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

The value should be an number indicating the number of seconds that a search query may span, e.g., 60 for one minutes, 86400 for one day.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

The value should be an number indicating the number of seconds that a search query may span, e.g., 60 for one minutes, 86400 for one day.

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...