Getting Data In

Timerange as an argument

Raghul_S
Engager

I am working on using the same time range as an argument used in the Time range picker.  how do I do that?

|metadata index=* type=hosts|eval First_Time=strftime(firstTime, "%Y-%d-%m %H:%M")

This is my search query and I need the "firstTime" values to be the same value as used in the search head (i.e) if this search is run from 1st Nov to 30th Nov, I need the firstTime values also in this specified time range as given in the time-range picker.

Labels (2)
0 Karma

Raghul_S
Engager

Hii, 
Thanks for responding, actually Implemented it in a different way using 2 queries!!
thanks anyway!

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Alpha Launch: AI-Assisted Auto-Schematization for CIM

Streamlining Data Onboarding: Announcing the Alpha Release of AI-Assisted Auto-Schematization For many Splunk ...

Enterprise Security(ES) Essentials or Premier? Let's discuss Splunk ES Editions on ...

  Hi everyone, Last year at .conf25, we shared something exciting: Splunk Enterprise Security is evolving ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 5

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...