I am working on using the same time range as an argument used in the Time range picker. how do I do that?
|metadata index=* type=hosts|eval First_Time=strftime(firstTime, "%Y-%d-%m %H:%M")
This is my search query and I need the "firstTime" values to be the same value as used in the search head (i.e) if this search is run from 1st Nov to 30th Nov, I need the firstTime values also in this specified time range as given in the time-range picker.
Hii,
Thanks for responding, actually Implemented it in a different way using 2 queries!!
thanks anyway!
It ain't that easy. In fact it might not be possible at all.
https://docs.splunk.com/Documentation/SplunkCloud/8.2.2111/SearchReference/Metadata#Time_ranges