I am trying to generate a report which i want to run at 2:30PM on 3 days a week only for the time range choosen as 1:25 PM to 1:30 PM how to pass the values earliest and latest in this case ?
is it like i have to convert the date and time to epoch time first and then pass it to earliest and latest or how to achieve in a simpler way?
@surekhasplunk , Can you try including time modifiers in earliest and latest like below-
index=<yourindexname> earliest=-65m latest=-1h
View solution in original post
| eval earliest=strftime(_time,"%m/%d/%Y").":13:25:00"
| eval latest=strftime(_time,"%m/%d/%Y").":13:30:00"
use sub search to send earliest and latest