Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Question regarding summary index with saved search

$
0
0
Hello, I have created a saved search to populate summary index. I am running saved search for every 5 minutes. What i want is, first time when the saved search runs, it should run with time range as all time. And from the second time on wards, saved search should with time range as "last 5 mins" (ie, latest=now and earliest=last time when ss ran succesfully) So that i will avoid duplicate of data in summary index. How to achieve this? Thanks in advance.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>