![Implementing Splunk 7(Third Edition)](https://wfqqreader-1252317822.image.myqcloud.com/cover/64/36700064/b_36700064.jpg)
上QQ阅读APP看书,第一时间看更新
Real-time
The custom Real-time option gives you the ability to set the start time for your real-time time range window. Keep in mind that the search time ranges for historical searches are set at the time at which the search runs. With real-time searches, the time ranges are constantly updating and the results accumulate from the beginning of your search.
You can also specify a time range that represents a sliding window of data, for example, the last 30 seconds.
When you specify a sliding window, Splunk takes that amount of time to accumulate data. For example, if your sliding window is 5 minutes, you will not start to see data until after the first 5 minutes have passed:
![](https://epubservercos.yuewen.com/DFC051/19470395608897106/epubprivate/OEBPS/Images/b5467b6b-f44c-4757-9a76-c6fe3511fd8d.png?sign=1739302560-vpluHnzMYumrgLA8QvRUq2ZAMYLbs4cn-0-b5aabe003f0c7e85cb0016c025653b7a)