Hello Experts,
I am having a search as below
|search | eval _time=new_t | timechart span=1mon sum(alloc) as used | streamstats sum(used) as "Total" | predict "Total" as "Projected" future_timespan=8
Output from the search is as below
_time | Used | Total | Projected | lower95 |
2019-09 | 1 | 1 | <some numbers> | <some numbers> |
2020-03 | 2 | 3 | <some numbers> | <some numbers> |
2020-04 | 4 | 7 | <some numbers> | <some numbers> |
2020-05 | 4 | 11 | <some numbers> | <some numbers> |
2020-09 | 5 | 16 | <some numbers> | <some numbers> |
2020-10 | <some numbers> | <some numbers> | ||
2020-11 | <some numbers> | <some numbers> | ||
2020-12 | <some numbers> | <some numbers> | ||
2021-01 | <some numbers> | <some numbers> |
How can i compare the "_time" field with current "month-year" and display only those rows greater than the current Year-Month.
| search _time>strftime(now(),"%Y-%m-%d")
Any hep will be appreciated ..Thanks
comparison of two times without convert them to epoch is difficult. converting just year and month to epoch time doesn't happen. I have added 01 as day for each months and compared. add below line to your SPL.
| where (strptime(strftime(_time,"%Y-%m-01"),"%Y-%m-%d"))> (strptime(strftime(now(),"%Y-%m-01"),"%Y-%m-%d"))
comparison of two times without convert them to epoch is difficult. converting just year and month to epoch time doesn't happen. I have added 01 as day for each months and compared. add below line to your SPL.
| where (strptime(strftime(_time,"%Y-%m-01"),"%Y-%m-%d"))> (strptime(strftime(now(),"%Y-%m-01"),"%Y-%m-%d"))
perfect thanks for the explanation ..appreciate it !!