http://docs.splunk.com/Documentation/Splunk/4.2.4/User/RealtimeSearch#Real-time_backfill
Realtime backfill, how is this implemented after its successfully configured?
Nothing extra is required. If default_backfill
is set to true in limits.conf (and note that true is the default value), then windowed realtime searches will automatically backfill right when you start them off.
Conversely, if you turn off the feature, then a 30 minute windowed realtime search will take 30 minutes before it's window is fully populated.
Nothing extra is required. If default_backfill
is set to true in limits.conf (and note that true is the default value), then windowed realtime searches will automatically backfill right when you start them off.
Conversely, if you turn off the feature, then a 30 minute windowed realtime search will take 30 minutes before it's window is fully populated.