Hi everyone
Someone who has used the map command who can help me, I am trying to bind the username of the 12 hours before the first search, but the result does not give any value
This is my query, maybe I'm doing something wrong
host=10.10.10.30 direction=in earliest=-15m latest=-1m| stats count by src_ip | map search="host=10.10.10.30 earliest=-12h latest=-15m src_ip=$src_ip$ username=*"
host=10.10.10.30 direction=in earliest=-15m latest=-1m
| stats count by src_ip
| map search="search host=10.10.10.30 earliest=-12h latest=-15m src_ip=$src_ip$ username=*"
see https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Map
host=10.10.10.30 direction=in earliest=-15m latest=-1m
| stats count by src_ip
| map search="search host=10.10.10.30 earliest=-12h latest=-15m src_ip=$src_ip$ username=*"
see https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Map
It is true, I miss adding that.
Thanks a lot