Hello Splunkers,
Well the question is as the title describes. What's the difference if I run a search with the two different time ranges? Do the two things both represent last 60 minutes? If I choose a "1 hour window", it will take more time than "last 60 minutes".
Thank you very much for your attention and help.
Daiyu
A search that displays a live and continuous view of events as they stream into Splunk Enterprise. With real-time searches and reports, you can search events before they are indexed and preview reports as the events stream in.
whereas
earliest=-60m will return data that has been indexed upto 60 mins before the time you execute the search. This is not a continuous view of events. Depending on your environment, there could be a delay between the time event occurred and the time it was indexed.