Hello everyone,
I am passing the dates as token but it shows the error in both the condition.
Cond1: | where (Date>="$date_start$" AND Date<="$date_end$")
Cond2: | where (Date>="2022-06-01" AND Date<="2022-06-02")
Please help
Hi @Neel88,
to compare dates, you have to transform them in epochtime using the strptime function, you cannot compare dates in text format.
The only apparent exception is _time, but it's only apparence because it's already in epochtime.
something like this:
<your_search>
| eval date_start=strptime($date_start$,"%Y-%m-%d"), date_end=strptime($date_end$,"%Y-%m-%d"), Date=strptime(date,"%Y-%m-%d")
| where Date>=date_start AND Date<=date_end
| ...
Ciao.
Giuseppe
Hi @Neel88,
this is a different problem:
in the simple xml dashboards you cannout use "<" or ">" but you have to use: "<" and ">"
Ciao.
Giuseppe
Thank you for your response.
| where (Date = ">","$date_start$") AND (Date = "<","$date_end$")
I am very new with this tool. I am not getting result.
Hi @Neel88,
I used quotes to delimit the strings, use them without quotes:
<your_search>
| eval date_start=strptime($date_start$,"%Y-%m-%d"), date_end=strptime($date_end$,"%Y-%m-%d"), Date=strptime(date,"%Y-%m-%d")
| where Date>=date_start AND Date<=date_end
| ...
Ciao.
Giuseppe
Thank you so much!! Its working fine 🙂