The subsearch with "makeresults" is generating custom time range, earliest and latest. Using it in the way mentioned here, will add (behind the scene) "earliest=<value> AND latest=<value>" in the subsearch using it. Since it happens behind the scene, syntax is not highlighted. | multisearch
[search index="abc" ]
[search index="xyz" [| makeresults | addinfo | eval earliest=relative_time(info_max_time,"-30d@d") | eval latest=info_max_time | table earliest latest]] Below search doesn't work because, earliest and latest is being added as field and not as filter. index="xxx"
| addinfo
| eval earliest=relative_time(info_min_time,"-30d@d")
| eval latest=info_max_time
| timechart span=1d count
... View more