Hi,
I have a search that shows the last time a server last had a virus update but how can I make the search so it only shows machines that have not had a virus update for say 14 days?
Thanks,
... your search here | where last_update < now()-(14*24*60*60)
now() in eval returns the current epoch time, 14*24*60*60 is the number of seconds in 14 days.
So we're checking if the last_update was before that.
Thanks can you break down what this bit of the search does
< now()-(14*24*60*60)
Thanks,