Splunk Search

Start time search in splunk

Nixon1023
New Member

How can I have a start time on my search, so that it starts every time reflecting the current time. I want to display a line chart/graph showing the beginning of my search as it progresses over time. My command so far is this......

source="/var/log/scenario1.log" | timechart span=5s max(host_bandwidth) by host

Tags (1)
0 Karma
1 Solution

Chubbybunny
Splunk Employee
Splunk Employee

per http://www.splunk.com/base/Documentation/latest/User/RealtimeSearch
under the section 'Specify real-time time range windows':

The syntax for real-time time modifers is:

rt[+|-]<time_integer><time_unit>@<time_unit>

You can find more information about the syntax for time modifiers in the topic, Change the time range of your search.

http://www.splunk.com/base/Documentation/4.2.1/User/ChangeTheTimeRangeOfYourSearch

View solution in original post

Chubbybunny
Splunk Employee
Splunk Employee

per http://www.splunk.com/base/Documentation/latest/User/RealtimeSearch
under the section 'Specify real-time time range windows':

The syntax for real-time time modifers is:

rt[+|-]<time_integer><time_unit>@<time_unit>

You can find more information about the syntax for time modifiers in the topic, Change the time range of your search.

http://www.splunk.com/base/Documentation/4.2.1/User/ChangeTheTimeRangeOfYourSearch

Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...