Hi,
I want to create a dashboard, similar to a gantt chart that has a bar between two fields derived by _time, LDAP sync start and LDAP sync end. I'm unsure on how to achieve this. There will be multiple instances of the two fields and I'd like to know how to group them together as well.
Here's my base search, currently only looks for latest:
index=index_name act="LDAP Synchronization start" OR act="LDAP Synchronization end"
| stats max(eval(if(act="LDAP Synchronization start", _time, 0))) as start max(eval(if(act="LDAP Synchronization end", _time, 0))) as end
| eval "LDAP Sync Start"=strftime(start,"%d/%m/%Y %H:%M:%S"), "LDAP Sync End"=strftime(end,"%d/%m/%Y %H:%M:%S")