Hi,
I am new to splunk and i have a minor problem.
When i created a report at the start time(dispatch.earliest_time) i would like to use an absolute time(like a date and time) but i don't know the correct format.
This is the format in the documentation but it is not working: 10/19/2009:0:0:0 I got this error: Encountered the following error while trying to update: In handler 'savedsearch': Cannot parse time argument 'dispatch.earliest_time': '2012-06-20T16:27:43.000-07:00'
Can someone point me to the correct format?
Thanks, laszlo
... View more