hello, splunker
I have question. plz
I want to search for a specific time range by specifying earliest and latest in the search.
E.g
I searched for "index="_internal" earliest=1 latest=now". And in timepicker, if you specify the last 15 minutes, the search will be done by timepicker time.
Why is this happening?
Any help and tips will be greatly appreciated!
Hi @ssbae your question was not clear..
"index="_internal" earliest=1 latest=now" ---if you used this search, Splunk will search all events/logs for "all time"
And in timepicker, if you specify the last 15 minutes, the search will be done by timepicker time // can you please check the "inspect job" and see what happened there.