Splunk Search

Buckets in splunk- Is it possible to do a 10 minutes from event not 10 minute window?

Mckechnie
Engager

Hi all,

Wondering if it is possible to do 10 minute search from when you see an event instead of doing 10 minute windows such as "| bin _time span=10m as window" as this just looks at minutes from the hour? 

Labels (1)
Tags (2)
0 Karma

johnhuang
Motivator

 

| bin _time span=10m aligntime=latest

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

Happy CX Day, Splunk Community!

Happy CX Day, Splunk Community! CX stands for Customer Experience, and today, October 3rd, is CX Day — a ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...