Uploaded by Sipisah Sip

Splunk Notes

advertisement
Working with Time
_time=12761461923
@ - is snap that round the time
Use that in search field
Default Time Fields
Round me Logs in between 2 minutes
Show me how many events happened in specific timeline
*** date* fields reflect time in only events
Download