Hi - looking for a more efficient way to do this, if anyone has any tips:
index=xyz sourcetype=abc NOT user_email=unauthenticated (user_email=*) | eval day=strftime(_time, "%Y%m%d") | search day=20210723 | ...
Basically, can I filter on _time for a specific day without doing the eval then filter, this seems like an inefficient way to query if I can somehow say dayOf(_time)='20201010' or something like that...
You can filter events using earliest and latest filter. Can you please try this?
index=xyz sourcetype=abc NOT user_email=unauthenticated (user_email=*) [| makeresults | eval earliest=strptime("20210723", "%Y%m%d"),latest=relative_time(earliest, "+1d@d") | table earliest latest | format] | ...
KV