Splunk Search

How to get a search in Splunk to show results from the last 24 hours and update in real-time every minute?

stefanlasiewski
Contributor

I know that Splunk can show me results for the last 24 hours. I also know that Splunk can show me results in real time, with times like a "1 minute window".

I would like to see Splunk search results from the 24 hours, and also update these results in real time. This way, I can log into Splunk, bring up my dashboard and get a sense of what happened in the last day and show me what is going on from here on out.

0 Karma

kml_uvce
Builder

use earliest time as rt-24h in your dashboard

kamal singh bisht
0 Karma

stefanlasiewski
Contributor

This isn't showing me data from the previous 24 hours. This seems to show me data from now on forward, and refreshes every 24 hours. Or at least, that is what my test with Earliest: rt-30m Latest=rt or with a "30 minute window" does.

0 Karma

acharlieh
Influencer
0 Karma

stefanlasiewski
Contributor

That's what I've been trying, but it's not updating in real time.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...