官术网_书友最值得收藏!

Using the time picker

Now that we've looked through all the widgets, let's use them to modify our search. First we will change our time. The default setting of All time is fine when there are few events, but when Splunk has been gathering events over a period time (perhaps for weeks or months), this is less than optimal. Let's change our search time to one hour.

The search will run again, and now we see results for the last hour only. Let's try a custom time. Date Range is an option.

If you know specifically when an event happened, you can drill down to whatever time range you want here. We will examine the other options in Chapter 2, Understanding Search.

Note

The time zone used in Custom Time Range is the time zone selected in the user's preferences, which is, by default, the time zone of the Splunk server.

主站蜘蛛池模板: 韶山市| 隆德县| 泊头市| 武陟县| 平乐县| 乌恰县| 丰原市| 新宾| 北京市| 富阳市| 鄂伦春自治旗| 璧山县| 思南县| 海盐县| 塔河县| 彰化市| 邓州市| 尼玛县| 天峨县| 泰州市| 东辽县| 合作市| 广德县| 大方县| 页游| 临邑县| 页游| 泽州县| 科技| 蒲江县| 平安县| 烟台市| 剑河县| 格尔木市| 定兴县| 五河县| 咸丰县| 衢州市| 黎川县| 乐东| 西丰县|