I know that Splunk can show me results for the last 24 hours. I also know that Splunk can show me results in real time, with times like a "1 minute window".
I would like to see Splunk search results from the 24 hours, and also update these results in real time. This way, I can log into Splunk, bring up my dashboard and get a sense of what happened in the last day and show me what is going on from here on out.
This isn't showing me data from the previous 24 hours. This seems to show me data from now on forward, and refreshes every 24 hours. Or at least, that is what my test with
Latest=rt or with a "30 minute window" does.