Unfortunately it looks like your answer doesn't solve my problem.
The matter is how gentimes command works. In the way you wrote it, it ALWAYS starts from yesterday, so my search will get up to end on today + 2 days. I need to have earliest time equal to the one on the main search, and latest time equal to the one on the main search +2 days.
This means I cannot use a constant in input to gentimes, like you did. I tried using the value of the choice made by the user, but it's not accepted as it is in "time picker" format (a string like '-1d@d'), and it looks like that format is not accepted in a different context.
What it seems to me is that Splunk is quite inconsistent in the way it allows timestamps and time-related values, in general, to be manipulated in different contexts.
... View more