Try something like this | eval root=mvjoin(mvindex(split(policy,"_"),0,1),"_")
| eval version=mvindex(split(policy,"_"),2)
| timechart span=48h values(version) as version by root
| eval date=if(_tim...
See more...
Try something like this | eval root=mvjoin(mvindex(split(policy,"_"),0,1),"_")
| eval version=mvindex(split(policy,"_"),2)
| timechart span=48h values(version) as version by root
| eval date=if(_time < relative_time(now(),"-2d"), "Last 48 Hours", "Today")
| fields - _time _span
| transpose 0 header_field=date column_name=policy
| eval "New version"=if('Last 48 Hours' == Today, null(), Today)