After populating data under summary index we are getting wrong timestamp for all the fields.
Original search query:
index=ABC sourcetype=XYZ subtype=### earliest=-90d@d latest=now | eval date=strftime(_time, "%m/%d/%Y") | stats count as Incoming, count(eval(action="blocked")) as Blocked by date |collect index=summary_index source="***"
Post Summary index query:
index=summary_index source="***"
However, when i run the above query, I lose the actual timestamp of the event. Instead, all events in the summary index have the current system time as the timestamp.
Change the Original Search like this
index=ABC sourcetype=XYZ subtype=### earliest=-90d@d latest=now |timechart span=1d count as Incoming, count(eval(action="blocked")) as Blocked | eval date=strftime(_time, "%m/%d/%Y") |collect index=summary_index source="***"
Change the Original Search like this
index=ABC sourcetype=XYZ subtype=### earliest=-90d@d latest=now |timechart span=1d count as Incoming, count(eval(action="blocked")) as Blocked | eval date=strftime(_time, "%m/%d/%Y") |collect index=summary_index source="***"
Thanks @somesoni2
The query worked & now we are getting correct timestamp for events.
They should also have a field called date yes?
If you want the full timestamp add _time to you stats command by clause:
... by date _time
like jkat54 said, ... | stats strips the time from results. add "by _time" to have that field