Archive
Highlighted

Searching on time

Explorer

Hi,

I have a search that shows the last time a server last had a virus update but how can I make the search so it only shows machines that have not had a virus update for say 14 days?

Thanks,

Tags (1)
0 Karma
Highlighted

Re: Searching on time

Influencer
... your search here | where last_update < now()-(14*24*60*60)

View solution in original post

0 Karma
Highlighted

Re: Searching on time

Explorer

Thanks can you break down what this bit of the search does

< now()-(142460*60)

Thanks,

0 Karma
Highlighted

Re: Searching on time

Influencer

now() in eval returns the current epoch time, 142460*60 is the number of seconds in 14 days.

So we're checking if the last_update was before that.