I used this query:
index="abc" source="xyz"
| search [inputlookup example]
| eval End=strptime("End_Date_Time","%Y/%m/%d %H:%M:%S") | eval Start=strptime("Start_Date_Time","%Y/%m/%d %H:%M:%S") | where (_time > End) OR (_time < Start)
This isn't returning any events. Any help?
There you go
index="abc" source="xyz"
[ | inputlookup example
| eval latest=strptime(End_Date_Time,"%Y/%m/%d %H:%M:%S") , earliest=strptime(Start_Date_Time,"%Y/%m/%d %H:%M:%S")
| eval maintenance="_time<"+earliest+" OR _time>"+latest
| return $maintenance]
Btw I had a typo in my answer, try this:
index="abc" source="xyz"
[ | inputlookup example
| eval latest=strptime(End_Date_Time,"%Y-%m-%d %H:%M:%S") , earliest=strptime(Start_Date_Time,"%Y-%m-%d %H:%M:%S")
| return earliest, latest]
Description End_Date_Time Requested_By Start_Date_Time Maintenance 2018/03/10 12:00:00 Sam 2018/03/10 01:00:00