官术网_书友最值得收藏!

Using the time picker

Now that we've looked through all the widgets, let's use them to modify our search. First we will change our time. The default setting of All time is fine when there are few events, but when Splunk has been gathering events over a period time (perhaps for weeks or months), this is less than optimal. Let's change our search time to one hour.

The search will run again, and now we see results for the last hour only. Let's try a custom time. Date Range is an option.

If you know specifically when an event happened, you can drill down to whatever time range you want here. We will examine the other options in Chapter 2, Understanding Search.

Note

The time zone used in Custom Time Range is the time zone selected in the user's preferences, which is, by default, the time zone of the Splunk server.

主站蜘蛛池模板: 乌拉特中旗| 涟水县| 岳普湖县| 苍梧县| 崇仁县| 招远市| 广平县| 荣昌县| 东兰县| 金坛市| 莫力| 马山县| 雷山县| 宣恩县| 本溪市| 呈贡县| 白山市| 甘洛县| 隆德县| 兴国县| 贵定县| 喀喇沁旗| 北碚区| 农安县| 丰都县| 建德市| 扶沟县| 乐至县| 湟中县| 镇沅| 泰顺县| 阳山县| 雅安市| 新野县| 凌云县| 年辖:市辖区| 齐河县| 若尔盖县| 阿尔山市| 尉犁县| 武夷山市|