Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

from command with time modifers

$
0
0
Hi all, I am trying to add time modifiers to "from" command ,from within the query, with not much of a luck. An example for the command is: | from datamodel:"Authentication"."Failed_Authentication" | search dest="Host1" app="win:local" Can anyone help me figuring this out ?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>