When I build the dashboard, I can see the last hour always not accuracy because the latest hour date is incomplete, take below as example. Assume that every hour we have 1000 events, but if I run the search in 03:30, it will got 500 events only, because another 500 events will come in next half hours.
However, if you use timechart to show last 4 hours, it will show the table like below. Is there a way I can show O'clock, but remove any data after the O'clock?
You can control the time window of your search, e.g. if you set the earliest to be -4h@h and the latest to be @h , e.g.
then you will get the previous 4 hours up to the last completed hour
Thanks for your help. But I need to use it in tstats command, and it will give error "'tstats' command: Invalid argument: 'earliest=-4h@h'" Do you know any other way. Better it can use in time picker as well.