How do I find whether the time stamp of an event covers a specific second within a day? So, we need to identify all the events for, let’s say, the second at the interval of 11:12:50 - 11:12:51.
| eval mytime=strftime(_time, "%d") but for the second...
hope i understood your question,
maybe use earliest and latest?
index = * sourcetype = * earliest = 7/31/2017:11:19:51 latest = 7/31/2017:11:19:52
you can also use the gui time picker for that
Perfect @adonio !!!
The following seems to work -
(earliest = 7/20/2017:20:00:00 latest = 7/20/2017:20:00:01) OR (earliest = 7/20/2017:21:00:00 latest = 7/20/2017:21:00:01) ....