A dashboard has a time range selector.
has a query search like below, the first search will apply the time range selector.
but the second search I want to set the earliest is the range selector earliest -7d@d
Does anyone know how to do this?
ex: today: 9/20, time range selector: 9/14~9/22,I excepted the second search is 9/7~9/22
index="*" host="...
| join type=left max=0 uid
[search earliest=??? latest=$earliest$ index="*" host="...
]
...
Thanks.
Try something like this
index="*" host="...
| join type=left max=0 uid
[search [| makeresults | addinfo | eval earliest=relative_time(info_min_time, "-7d@d") | eval latest=info_min_time | table earliest latest ] index="*" host="...
]
Try something like this
index="*" host="...
| join type=left max=0 uid
[search [| makeresults | addinfo | eval earliest=relative_time(info_min_time, "-7d@d") | eval latest=info_min_time | table earliest latest ] index="*" host="...
]
wow, amazing...this is the result I want
Respect!
Thanks a lot.