I then attempt to use it and modify the results with tokens like so:
<query>| search type IN ($types$) AND account IN ($accounts$) | stats count by hostname | sort -count </query>
The new search modifications with tokens works. However, no matter what I do, the time picker does not work. I only ever get back the last 30 minutes of data. I thought the 7 day retention meant I could get back any amount of time up to 7 days back quickly, not just the last 30 minutes.
I tried to work around this by running this but the same thing happens: