Some questions about indexed rt (http://docs.splunk.com/Documentation/Splunk/6.2.2/Search/Aboutrealtimesearches#Indexed_real-time_search) apparently i can't post a link--so search for indexed realtime at splunk docs if you don't know what it is.
the docs says setting indexed_realtime_use_by_default = true sets indexed rt to be the "default" behavior. if this is enabled, is there still a way I can run "normal", pre-indexer rt searches, perhaps with some search argument or command?
is there a way to make indexed rt the default for a role, but allow other roles to use normal rt?
are there any guidelines on best practices for setting indexed_realtime_default_span?
thanks,
bw
... View more