I have a requirement where my fiscal year starts in 1st SEP and my day starts counting at 7am and ends at the next day 7am instead of the usual 23:59:59.
Are there any way I can redefine what is a day in Splunk?
↧