Hi, I am new to splunk so pardon me if made any mistake or asking simple questions, i need to extract data from XML files, only when the xml parameter date is in current date and my date filed (printed-Timestramp) is in this format "2020-06-20T01:23:23.693-0700"
i tried below query now i need to pass the XML Parameter printed-Timestramp , please correct me for the best way to get the result
| makeresults | eval substrng=strptime(substr("2020-06-20T01:23:23.693-0700",1,10),"%Y-%m-%d")| eval compare=now() | where compare<substrng | fields + substrng,compare
below arethe reference of my xml file
| makeresults | eval epoch=strptime("2020-06-20T01:23:23.693-0700","%FT%T.%3Q%z")
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Commontimeformatvariables
now() is epoch. please try this query.