<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Want to change the epoch value dynamically using variable in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Want-to-change-the-epoch-value-dynamically-using-variable/m-p/520260#M146498</link>
    <description>&lt;P&gt;what's the error ?&lt;/P&gt;&lt;P&gt;Tried below and working fine&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|makeresults count=5|eval epochtime=now()|eval epochtime=epochtime - 10
|where epochtime &amp;lt; now()&lt;/LI-CODE&gt;</description>
    <pubDate>Fri, 18 Sep 2020 07:55:11 GMT</pubDate>
    <dc:creator>renjith_nair</dc:creator>
    <dc:date>2020-09-18T07:55:11Z</dc:date>
    <item>
      <title>Want to change the epoch value dynamically using variable</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Want-to-change-the-epoch-value-dynamically-using-variable/m-p/520249#M146496</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to change the EPOCH value in search having where clause in datamodel using variable but not working&amp;nbsp; so please help as i have tried different options but didn't work.&lt;/P&gt;&lt;P&gt;from datamodel=Qualys_prod_ext.Qualys_prod where (nodename = Qualys_prod) Qualys_prod.QID=* Qualys_prod.IP=* Qualys_prod.owner="SRE-DIS-ECO-FEA" Qualys_prod.managed=* Qualys_prod.sev="*" Qualys_prod.LAST_FOUND_DATETIME_EPOCH &amp;lt;&lt;SPAN&gt;1600411282&lt;/SPAN&gt; AND Qualys_prod.LAST_FOUND_DATETIME_EPOCH &amp;gt; 1596808800 groupby Qualys_prod.IP, Qualys_prod.signature, Qualys_prod.owner, Qualys_prod.QID, Qualys_prod.CVSS_CUSTOM, Qualys_prod.FIRST_FOUND_DATETIME|search Qualys_prod.STATUS=* NOT Qualys_prod.STATUS=FIXED&lt;/P&gt;&lt;P&gt;so want to change from Qualys_prod.LAST_FOUND_DATETIME_EPOCH &amp;lt; &lt;SPAN&gt;1600411282&lt;/SPAN&gt;&amp;nbsp;to Qualys_prod.LAST_FOUND_DATETIME_EPOCH &amp;lt; epochtime variable but having where clause error. I have defined the variable like&lt;/P&gt;&lt;P&gt;| eval epochtime=now()&lt;/P&gt;&lt;P&gt;but didn't help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 06:45:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Want-to-change-the-epoch-value-dynamically-using-variable/m-p/520249#M146496</guid>
      <dc:creator>saleem_i8</dc:creator>
      <dc:date>2020-09-18T06:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Want to change the epoch value dynamically using variable</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Want-to-change-the-epoch-value-dynamically-using-variable/m-p/520260#M146498</link>
      <description>&lt;P&gt;what's the error ?&lt;/P&gt;&lt;P&gt;Tried below and working fine&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|makeresults count=5|eval epochtime=now()|eval epochtime=epochtime - 10
|where epochtime &amp;lt; now()&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 18 Sep 2020 07:55:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Want-to-change-the-epoch-value-dynamically-using-variable/m-p/520260#M146498</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-09-18T07:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: Want to change the epoch value dynamically using variable</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Want-to-change-the-epoch-value-dynamically-using-variable/m-p/520270#M146502</link>
      <description>&lt;P&gt;&lt;SPAN&gt;from datamodel=Qualys_prod_ext.Qualys_prod where (nodename = Qualys_prod) Qualys_prod.QID=* Qualys_prod.IP=* Qualys_prod.owner="SRE-DIS-ECO-FEA" Qualys_prod.managed=* Qualys_prod.sev="*" Qualys_prod.LAST_FOUND_DATETIME_EPOCH &amp;lt; now() AND Qualys_prod.LAST_FOUND_DATETIME_EPOCH &amp;gt; 1597759200 groupby Qualys_prod.IP, Qualys_prod.signature, Qualys_prod.owner, Qualys_prod.QID, Qualys_prod.CVSS_CUSTOM, Qualys_prod.FIRST_FOUND_DATETIME|search Qualys_prod.STATUS=* NOT Qualys_prod.STATUS=FIXED&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When i change the search from&amp;nbsp;Qualys_prod.LAST_FOUND_DATETIME_EPOCH &amp;lt; 1600417128 to Qualys_prod.LAST_FOUND_DATETIME_EPOCH &amp;lt; now() it throws an error&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Error in 'TsidxStats': WHERE clause is not an exact query&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 08:24:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Want-to-change-the-epoch-value-dynamically-using-variable/m-p/520270#M146502</guid>
      <dc:creator>saleem_i8</dc:creator>
      <dc:date>2020-09-18T08:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: Want to change the epoch value dynamically using variable</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Want-to-change-the-epoch-value-dynamically-using-variable/m-p/520537#M146556</link>
      <description>&lt;P&gt;Any other suggestion please?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 03:06:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Want-to-change-the-epoch-value-dynamically-using-variable/m-p/520537#M146556</guid>
      <dc:creator>saleem_i8</dc:creator>
      <dc:date>2020-09-21T03:06:26Z</dc:date>
    </item>
  </channel>
</rss>

