I have an alert query which runs after every 30 minutes and has a relative time range of last 30 minutes. There is a mail action triggered on this search in which i have send $job.earliesttime$ and $ job.latesttime$ which gives me the time period of this search but i need to change the format of this time period to utc .
How can i do it.
As @niketnilay mentioned,
1. You can use
addinfo command to get 'Job search time'.
2. Format the timestamp using
strftime as below.
| makeresults | eval message="My Email Message" | addinfo | eval job_search_time=strftime(info_search_time,"%d-%m-%Y") | table message,job_search_time
And, you can include the custom field in your email subject/body using
@ajitshukla61116 You can pipe the addinfo command to your existing search for alert and get info_min_time and info_max_time as earliest and latest time as epoch. Then you can use strftime() to convert epoch time to your expected string time.