Hi,
I need to find a way to look for events in "All Time", but only during specific hours, e.g. between 9am and 5pm.
Any suggestions?
Thanks!
As stated below, date_hour is the field to operate on. It is extracted/created for almost all types of log - but not for windows event logs. Bleh.
/k
example
index=cisco_esa (date_hour<=16 AND date_hour>=9)
9am to 4:59:59:999pm
it will bucket the events using 1hr slots, so you get 8 slices per day, but you can modify that is needed, etc.