Hello,
I am looking for a Splunk query that could match date as below.
"*Execution failure in Transferring Transaction Billing File :: 210609*"
This is the logs I get for a file transfer with yesterdays date, how can search that could replace the static date to dynamic. I want a query that could search for above texts and equivalent yesterdays everyday.
Actually I was trying to use this query, but it sis not working as expected.
index=securecode host IN (cjb4stl181) sourcetype=securecode:billing:txn_gft "*Execution failure in Transferring Transaction Billing File :: " .strftime(relative_time(now(), "-1d@d"), "%y%m%d") . "*"