I am trying to trend some metrics for the first Wednesday of each month, over a time range of 6 months. I have something like this, but it keeps spinning saying its scanning events, but no events shows up (when I expect to see a lot for the Wednesdays)
index=ABC earliest=05/01/2010:00:00:00 latest=01/13/2011:00:00:00 date_wday=Wednesday date_mday>=1 date_mday<=7 | ....
I am using 4.1.4.3, build 89226
It keeps scanning events, but never seems to get any back. I think something is wrong in the query syntax, but Splunk is not failing on it, its just working hard to find nothing.
... View more