hi All,
is their way alert(search query) can distinguish between weekdays, weekends, monthend?
Thanks
Sathish R
Like this:
... | eval now=now() | eval date_wday=strftime(now, "%a") | eval weekday=if(date_wday="Sat" OR date_wday="Sun","NO","YES") | eval date_mday=strftime(now, "%d") | eval tomorrow=now+86400 | date_mday_tomorrow=strftime(tomorrow, "%d") | eval monthend = if(date_mday>date_mdate_tomorrow,"YES","NO") | fields weekday monthend