I created a search of the log application running on a 24/7, in which I set the schedule type Basic and run every 5 minutes. In response I get irregular time events such as: 4:57, 4:47, 4:42, 4:32, 4:7, 3:57, 3:52, 3:42, 3:37, 3:32, 3:7. Why it happens.
Thanks.
maybe your log are timestamped and splunk uses this time as time events