Hey guys, i have | eval Date=strftime(strptime(data,"%Y/%m/%d"),"%m/%d") returning
but i want to receive only the last 4 days.
The data is in a lookup_table csv
String comparisons are usually bad news. Consider this instead:
| where strptime(data,"%Y/%m/%d") >= relative_time(now(), "-4d")
That way the comparison is done using numbers / epoch time, so there's no ambiguity in case your date formatting requirements change.
View solution in original post
ok, i think i found what i need:
| where Date >= strftime(relative_time(now(), "-4d"), "%m/%d")