I have data that has _time from 18:00:20-18:00:52 and I set my current time to 18:01 so it should search the 18:00 time, why is it not working (display an empty result)? It should display the data from 18:00:20-18:00:52.
this is my search:
your search has no result. your index or source are correct?
View solution in original post
index=_internal earliest=-1m latest=@m | stats min(_time) as A max(_time) as B count | convert ctime(A) ctime(B) |addinfo | foreach *time [ eval <<FIELD>>=strftime('<<FIELD>>',"%T")]
Maybe we should unify with @.
It displayed this one:
Hi, I finally found my mistake, it seems my _time was wrong, so the search returns an empty result, big thanks!
good job @mathiasy123 happy splunking!
How to check if my index and source are correctly?
check data summary on search
How to do it ?
click "Data Summary"
Okay, let me try it.