Hi IRHM73,
try this search:
|rest /services/search/jobs
|rename custom.search as customSearch
|search NOT author="splunk-system-user"
|eval SearchString=if(isnotnull(customSearch),customSearch,eventSearch)
|search SearchString!=""
|addtotals fieldname=duration *duration_secs
|eval groupduration=case(duration<=300, "Less Than 5 Minutes", duration>300 AND duration<=600, "Between 5 and 10 Minutes", duration>600 AND duration>=1200, "Between 10 and 20 Minutes", duration>1200, "Greater Than 20 Minutes" )
|convert rmunit(duration) as numSecs
|eval stringSecs=strftime(numSecs, "%Mm %Ss %2Nms")
|eval earliestTime=strptime(earliestTime, "%Y-%m-%dT%H:%M:%S")|convert timeformat="%d/%b/%Y" ctime(earliestTime)
|eval latestTime=strptime(latestTime, "%Y-%m-%dT%H:%M:%S")|convert timeformat="%d/%b/%Y" ctime(latestTime)
|eval daterange= "From: ".earliestTime.", To: ".latestTime
|makemv delim=", " daterange
|sort +author
|table author,SearchString , daterange, request.earliest_time, request.latest_time, duration, stringSecs
|rename author as "Author", SearchString as "Search Performed", earliestTime as "Earliest Date Used", latestTime as "Latest Date Used", request.earliest_time as "Earliest Time Query Setting", request.latest_time as "Latest Time Query Setting", stringSecs as "Query Runtime"
cheers, MuS
... View more