Implementing Splunk 7(Third Edition)
上QQ阅读APP看书,第一时间看更新

Different ways to search against time

Now that we have our time indexed properly, how do we search against time? The Date & Time Range picker provides a neat set of options for dealing with search times:

This picker widget is organized by:

  • Presets
  • Relative
  • Real-time
  • Data Range
  • Date & Time Range
  • Advanced

Let's take a look at each of these.