This should get you started:
... | rex field=URL "(<?PbaseURL>\/\w+\/\w+\/\w+)" | stats sum(time) as totalTime by baseURL | table baseURL totalTime
... View more
Yeah, to the very end.
info_min_time is a field added by addinfo , containing the minimum end of the time range set by earliest .
http://docs.splunk.com/Documentation/Splunk/6.2.3/SearchReference/addinfo
... View more
Hi,
I have a similar question. My inner search returns the date and time(for eg 06-22-2015-23). I want to use this time in my outer search as earliest time = "06-22-2015-23" and latest should be one hour after that(06-23-2015-00) i.e one hour post the earliest time.
For eg.
"outer search" [search ... | eval MyLatestTime=_time | fields + MyLatestTime | rename MyLatestTime as earliest] latest= earliest+1
Thanks in advance
... View more