can anyone help me to write a Splunk query for when I have an outage I'd like a query executed that shows the duration of the outage.
Are you looking for splunk outage?
NO .. If I check 5XX or 4XX errors, It will show some logs in hour 5 or 10 mins period ex: I checked 500 errors 10pm to 11pm... in that one hour, errors started from 10:15pm to 10:45pm , I want only period {10:15pm to 10:45pm } no need logs .. for that How I need to write quarry