Hello All,
Suppose I want a search results for past 60minutes, how spunk works now is if there is any event in past 60mins then that is displayed.
But what i want is Suppose time is 4pm and I give past 60mins, Splunk should start the data from 4:00, 4:01...... and so on till 5:00 irrespective of data is present or not, if data is not present then the result should give time with corresponding columns blank.
Can someone please help mw on this.
↧