Getting Data In
Highlighted

return yesterday count on: ---| eval filename=strftime(now(), "xyz_%d.csv

Explorer

Hello,

I am running below search; daily (last 24h) .... which returns results and "outputlookup" results into a csv based on "xyzNOof_day"

Runs fine....if I am running such search on same day (i.e. close to midnight) but the source get inputs after midnight so I miss data and had to run such search next day..... i.e. running 04:30am following day
Running next day same search and setting it will return a file name based of the day (next-day)

So I like to run the search on next day.... i.e. running the search on day 09 @ 04:30am (search day before, which is day8) ... it should | eval filename=strftime(now(), "Application-license-usage-perday%d.csv") %d must be counted as the day before =8 not 9.

I tried without results to:

| outputlookup [ | stats count | eval filename=strftime(now(), "-1d", "Application-license-usage-perday%d.csv") | return $filename]

Do you have any idea how to fix it?

below is the initial search
index="application-license" sourcetype=application LicenseUserdevice=* Licensefeaturestatus="OUT" Licenseuser=*
| eval License
featurestatus=(Licensefeaturestatus)
| eval License
Userdevice=split(LicenseUserdevice,",")
| eval License
user=split(Licenseuser,",")
| makemv delim="," License
user
| mvexpand Licenseuser
| sort License
user
| dedup Licenseuser
| stats list(License
user) as "User" list(LicenseUserdevice) as "Computer" count(Licensefeaturestatus) as "LicenseTaken" by _time

| outputlookup [ | stats count | eval filename=strftime(now(), "Application-license-usage-perday%d.csv") | return $filename]

Thanks in advance

Highlighted

Re: return yesterday count on: ---| eval filename=strftime(now(), "xyz_%d.csv

Influencer

hi @knitz,

Subtract 86400 (seconds for 1 day) from now().

| eval filename=strftime(now()-86400, "Application-license-usage-per_day_%d.csv")

View solution in original post