i have 1 field with date and time trigger_time_rendered |rest /servicesNS/admin/search/alerts/fired_alerts/-
|fields eai:acl.owner savedsearch_name triggered_alert_count trigger_time_rendered
| eval
timestamp=strptime(trigger_time_renderede,"%Y/%m/%d%H:%M:%S"),
trigger_time_earliest=strptime($trigger_time_rendered.earliest$,"%Y/%m/%d%H:%M:%S"),
trigger_time_latest=strptime($trigger_time_rendered.latest$,"%Y/%m/%d%H:%M:%S")
| search timestamp>trigger_time_earliest timestamp<trigger_time_latest
| join savedsearch_name [
| rest splunk_server=local count=0 /services/saved/searches
| rename title as savedsearch_name
| lookup mailingList.csv "action.email.to" OUTPUT teamName
| table action.email.to savedsearch_name teamName] the fact that it contains also the TZ related ? maybe it should be also part of the convert ?
... View more