I want to write a splunk query which will run over the same timewindow but on a different date selected in the datetime picker.
For ex. lets say I select 8th aug 10am to 8th august 10:15am range in the datepicker my query should give me result for the timewindow 1st aug 10am to 1st aug 10:15am.
index="_internal"
[| makeresults
| addinfo
| eval earliest=relative_time(info_min_time, "-7d")
| eval latest=relative_time(info_max_time, "-7d")
| fields earliest latest]
index="_internal"
[| makeresults
| addinfo
| eval earliest=relative_time(info_min_time, "-7d")
| eval latest=relative_time(info_max_time, "-7d")
| fields earliest latest]