Hello Splunkers!!
I am facing an issue while running below search. As you can see in the screenshot. Can anyone help me to fix this issue.
search query :
| makeresults
| addinfo
| eval earliest=max(trunc(info_min_time),info_min_time),latest=min(max(trunc(info_max_time),info_max_time+0),2000000000)
| map search="search `indextime`>=`bin($earliest$,300)` `indextime`<`bin($earliest$,300,+300)` earliest=`bin($earliest$,300,-10800)` latest=`bin($latest$,300,+300)``"
| where false()
Screenshot for a query error:
[| makeresults
| addinfo
| eval search="_indextime>=".tostring(300*trunc(info_min_time/300))." _indextime<".tostring((300*trunc(info_min_time/300))+300)." earliest=".tostring((300*trunc(info_min_time/300))-10800)." latest=".tostring((300*trunc(info_max_time/300))+300)
| fields search] `scada_alarms`