...r 4 days if I get the information. By discard it is because of the time it is taking, I don't know if I'm wrong but there is some configuration that limits a maximum timein seconds until it g...
I have a dropdown selection for a Policy field. I want to be able modify the searchtime based on the policy selected in the dropdown.
The drop down has 3 static options and depending on what i...
Hey everyone,
I've got a query here that I'm using to find values over 3 different periods of time. Today, yesterday and two days ago. I've made this query into a report and attached it to a d...
...oth in the same 12 hour time frame. " < 26-Mar-2021 12:59:56 o ' clock AM MDT > < Error >......" I am trying to run a search based on a dashboard panel that is using the m...
I have a dashboard which uses tokens that look like this
earliest=$TIME.earliest$ latest=$TIME.earliest$+60s
If I use the timerange picker and select a relative time, the search works as e...
...ow.
Is it possible to do this with only one "search" ?
Today i use 2 searchs which are the same instead the time-modifiers:
For the week-end view:
earliest_time = @w1-2d-6h
l...
I have a situation where I want to run a main search of one index over a time period driven by the time picker on a dashboard, but annotate the results with information from a second search. The s...
Hi!
Is it possible to do something like below possible?
If I have 5 searches ,
search A
search B
search C
search D
search E
and specifytimemodifier , for example , as e...
...am reading documentation about setting up search-time field extraction in props.conf. I have been playing around with it and it's not behaving as expected. However, I just realized, I'm not sure if I...