I want to create below search using splunk DataModel:
index="oqapub" sourcetype="ideskdbinc" |search RESOLVERGROUP="ABC" |eventstats earliest(time) as ticketstarttime |eventstats latest(time) as ticketendtime| where isnotnull(LASTRESOLVEDDATE) AND (LASTRESOLVEDDATE >= ticketstarttime AND LASTRESOLVEDDATE <= ticketendtime) | where NOT DETAILEDDECRIPTION like "%bamAudit%" |where STATUS !=6|dedup INCIDENTNUMBER|chart count(INCIDENTNUMBER)
but when I am trying to put "ticketstarttime" and "ticketendtime" in eval expression, it gives me an error in pivot
"Error in 'eval' command: The expression is malformed. "
Any help would be highly appreciated.
eventstats is not an
eval function. You can find all
eval functions here https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Eval#Functions
As for your use case, you might have to provide some samples and more detail what it is that you want to achieve.
Hope this helps ...
From this query, I am.looking to find out number of incidents which have been resolved by my team during particular duration.
Intent is to create splunk data model and provide it to my team to find themselves incident count.
While creating splunk data model, I.am unable to find how do I use ticketstarttime" and "ticketendtime" in eval expression as it is only option I have in splunk data model creation. As soon as I go to pivot to analyse my data model, I start getting error "Error in 'eval' command: The expression is malformed".
Hope I have been able to explain.