Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to use a date format as a filter in the base search

$
0
0
Hi, I have events with a timestamp_value=1477043785561 We can filter like this: index=a sourcetype=logins timestampvalue<=1477008000 Is it possible to use a date format in the base search to filter? Of course the following does not work, but perhaps something similar is possible so that I don't have to translate every filter into epochtime. index=a sourcetype=logins timestampvalue<=2016-10-21 Best Heinz

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>