When I put "sourcetype="splunk_member_info2" | timechart count" on SEARCH,
the result shows monthly result. (Log is collected for about 5 years.)
I want to see the daily result.
is it possible?
When I put "sourcetype="splunk_member_info2" | timechart count" on SEARCH,
the result shows monthly result. (Log is collected for about 5 years.)
I want to see the daily result.
is it possible?