How to find a list of hosts that have not reported in, in a week. I tried the following but not producing any results.
... | eval etime=strptime(time, "%d/%m/%Y"), sevenDaysAgo=relative_time(now(), "-7d")
| where etime < sevenDaysAgo
Hi @SamHTexas,
You can use below search;
| metadata type=hosts index=_*
| eval a=recentTime-lastTime
| where recentTime-lastTime>86400*7
| convert ctime(*Time)