Hello,
Can you tell me please why the below does not work?
| rest splunk_server=local servicesNS/-/-/data/ui/views/
| where update > relative_time(now(),"-10d@d")
I want to search the dashboards that were updated in the last 10 days but it does not seem to return anything. Is it because I need to fix the timestamp format?
Thanks!
| rest splunk_server=local servicesNS/-/-/data/ui/views/
| where strptime(updated,"%FT%T") > relative_time(now(),"-10d@d")
| rest splunk_server=local servicesNS/-/-/data/ui/views/
| where strptime(updated,"%FT%T") > relative_time(now(),"-10d@d")