Hello, I am interested in making the results of one index search (in particular the values of fields early and late) used in a different index search as values assigned to earliest latest. index="a" <find a specific event> | eval timeTOsecs=strftime(_time, "%s") | eval early_time= timeTOsecs-300 | eval late_time= timeTOsecs+300 | eval early=strftime(early_time, "%m/%d/%Y:%H:%M:%S") | eval late=strftime(late_time, "%m/%d/%Y:%H:%M:%S") My next search would search for all events using the early and late values of the previous search and assign them to earliest latest. index="b" earliest=early latest=late Everything I have tried up to this point seems to point to "earliest" and "latest" modifiers will not allow you to assign a field value to them. Essentially I want to perform the function that Splunk automates through its UI when it lets the user run a search on events before and after a given time. Thanks for anyone that can help me and let me know if I can be clearer in explaining because sometimes it is hard to understand other people's context.
... View more