Hello,
Is it possible to start a search (or report, chart, etc) which will display the last 15 minutes of events, and will continue to display in real time?
This would be like specifying -15m, rt or -1h, rt
Thanks, Jean
Hi Jean,
With current Splunk (as of 4.1) this is not possible.
http://answers.splunk.com/questions/3659/combining-historical-and-realtime-searches