Hello Splunk team, I have two doubts please help me with details,
1. We are using Splunk cloud platform for Enterprise security. Is there any way to know the time span of buckets for how many days ...
See more...
Hello Splunk team, I have two doubts please help me with details,
1. We are using Splunk cloud platform for Enterprise security. Is there any way to know the time span of buckets for how many days we have configured. For example Hot - 90 days Warm- 90 days like this data how to get to know from Splunk GUI, I have used "| dbinspect" in search query but I am unable to get the timing for how many days we have kept Hot, warm etc.,
2. While using a search query we can see the time range "All Time", so here what does it actually mean. Is this mean from when we have configured Splunk or from when logs got ingested or else only the Hot & Warm buckets database data. Thanks in advance for letting me know the details.