index=_internal earliest=-1m latest=@m | stats min(_time) as A max(_time) as B count | convert ctime(A) ctime(B) |addinfo | foreach *time [ eval <<FIELD>>=strftime('<<FIELD>>',"%T")]
Maybe we should unify with @.
your search has no result. your index or source are correct?
Hi, I finally found my mistake, it seems my _time was wrong, so the search returns an empty result, big thanks!
good job @mathiasy123 happy splunking!
How to check if my index and source are correctly?
check data summary on search
click "Data Summary"