I am using Splunk DB Connect to take the database data in to Splunk.
In that data, i have a data field name as update_date
In my dashboard, i would like to search the data based on the update_date and should take the input datetime from the timepicker drop-down.
i want search all updated data between x-date to y-date. Or updated date =x-date should display all the data on that updated data.
My updateddate and _time (indexing times) are different. My updateddate is in _raw.
In search, I am taking different sources data using "left join"