I've got all our firewall logs going into separate index.
When I perform a search just using the index as a value, for example index="sec-firewalls" the results vary quite a bit.
I get nothing for real-time unless I select all time (real-time). Under relative results I get nothing for today. Nothing for last 15 minutes, last 4 hours etc. Again, the only option that works is All time.
When I'm looking at real-time results, it's about 2hr30m behind.
I am using the Splunk Add-on for Cisco ASA for this index.
Anyone able to assist me with what's happening here?