I’ve been running into an issue with the Splunk query which have been using since long time and seeing the following error message: “Please select a shorter time duration for your query,” even when I’m using a 5-minute time range.
I noticed that this error seems to pop up when we use latest=now() in our queries to get the most recent data.However, when I tried the same query with a specific time range, like earliest=-xxh@h latest=-xxh@h, it worked just fine.
Any ideas on why latest=now() might not be fetching results as expected? And if there is any resolution to working with latest=now()
Hi
have you check / asked it there is Splunk Workload management rules implemented for this search?
r. Ismo