I want to take the earliest and latest _time and assign to some other timestamp column. For example, I have a timestamp column Transaction Date which is NOT _time and I want to use this in the search command to achieve the below
Index = test | where Transactiondate => earliest and Transactiondate <= latest
Can you please help me.
Not sure what is epoch time and why to convert that. I have timestamp like "2016-08-05 12:00:00.0"