Hello,
I am trying to use another field (LAST_FIXED_DATE) as _time in my log search. LAST_FIXED_DATE got dates from 2008, 2009.....2020.
But I just want to find data for LAST_FIXED_DATE value from last 6 months. (example: Nov 2019 till April 2020)
Below query is not working, and still shows me _time value from 2008.
My query:
main search ....
| eval _time=strptime(LAST_FIXED_DATE,"%Y-%m-%d")
| table _time
Results what I see:
2008-06-30
2008-06-01
I just want _time to show values for last 6 months, and not back to 2008.
I have tried adding earliest and latest, but then I get no results.
The earliest
and latest
settings work with _time so they won't help. You'll have to constrain the results yourself using where
.
main search ....
| eval _time=strptime(LAST_FIXED_DATE,"%Y-%m-%d")
| where _time > relative_time(now(), "-6mon")
| table _time
The earliest
and latest
settings work with _time so they won't help. You'll have to constrain the results yourself using where
.
main search ....
| eval _time=strptime(LAST_FIXED_DATE,"%Y-%m-%d")
| where _time > relative_time(now(), "-6mon")
| table _time
try this
| eval _time = strptime(substr(LAST_FIXED_DATE,1,10), "%your%format%string%here%") | where (_time >= $info_min_time$ AND _time <= $info_max_time$)