splunk / security_content

Splunk Security Content
https://research.splunk.com
Apache License 2.0
1.3k stars 362 forks source link

remove endhoursago=1 from drilldown searches #3173

Closed patel-bhavin closed 2 weeks ago

patel-bhavin commented 3 weeks ago

Remove endhoursago=1 as it doesnt work on our testing. Rely on $info_max_time$ for the latest offset. Screenshot to show the _time span (highlighted)

Also update name for better formatting on Incident Review

image