Hi Team,
We have three time fields
Time - Indexed time( CSV file uploaded time)
Last_uploaded - Microservices latest deployed time
Running_since - Microservices start time
All time fields are in "%+" (Fri Apr 24 05:00:20 +08 2020) format and are in the same timezone
Below fields are getting pushed to splunk through csv file
Time,Org,Space,Microservices,State,Stack,Buildpacks,Last_uploaded,Total_instance,Running_instance,Instance_state,Running_since,Used_CPU,Used_memory_bytes,Total_memory_bytes,Used_disk_bytes,Total_disk_bytes
Please help in how to create input panel for Last_uploaded, Running_since & what would be the query for the below requirement
How to query all microservices deployed between particular dates example ( 14th April to 16th April )
How many microservices were started between particular days example ( 17th April to 20th April )
Tired few options but no luck luck
| eval _time=strptime(Time,"%+") | eval Latest_deployment_time=strptime(Last_uploaded,"%+") | eval Instance_start_time=strptime(Running_since,"%+")
Regards,
Thomas Mathias
... View more