I have a sourcetype with the following:
_time, host, contacttime
2015-07-14 02:01:02.353 ZEUS 2014-01-23 12:53:19
(before any one asks, _time is when the event was 'imported', long story)
I'd like to:
1. be able to use time modifiers on contacttime
2. as an example, with the time modifiers be able to filter out any events that have a contacttime>3 months
Any assistance would be greatly appreciated.
If you really need to use time modifiers, you can do this:
... | eval _time=contacttime | <your search with modifiers here>
However you can work with contacttime directly like this:
| eval contactepoch=strptime(contacttime, "%Y-%m-%d %H:%M:%S") | where contactepoch<(now()-3*31*24*60*60)
View solution in original post
Thanks for the prompt response.