Splunk Search

Buckets in splunk- Is it possible to do a 10 minutes from event not 10 minute window?

Mckechnie
Engager

Hi all,

Wondering if it is possible to do 10 minute search from when you see an event instead of doing 10 minute windows such as "| bin _time span=10m as window" as this just looks at minutes from the hour? 

Labels (1)
Tags (2)
0 Karma

johnhuang
Motivator

 

| bin _time span=10m aligntime=latest

 

0 Karma
Get Updates on the Splunk Community!

Notification Email Migration Announcement

The Notification Team is migrating our email service provider from Postmark to AWS Simple Email Service (SES) ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...