I need some help to filter by time, but the time field is not the internal Splunk time field. Instead, it is a date field from a lookup spreadsheet that corresponds to the objects file creation.
I want to be able to filter on objects that are created only in the previous month.
The format of the lookup date field is like this:
You can create _time field right in search query, like this:
| eval _time=strptime(Created,"%Y-%m-%d %H:%M:%S")