Hi,
is it possible to define eventtypes or tag directly to search results, so that the selected timerange is used as well as a condition?
I think it can be done by using the this kind of search string in the eventtype manager:
sourcetype=ABC eventname=error AND _time>1432684800 AND _time<1432771200
But the described scenario above would be much easier to handle.
BR
Heinz
For eventtypes, I have been doing exactly what you are describing with no issues. I use this for my time range as it is a bit easier on the eyes.
host=myhost1 sourcetype=Source1 earliest="05/28/2015:08:00:00" latest="05/28/2015:12:00:00"
For eventtypes, I have been doing exactly what you are describing with no issues. I use this for my time range as it is a bit easier on the eyes.
host=myhost1 sourcetype=Source1 earliest="05/28/2015:08:00:00" latest="05/28/2015:12:00:00"
Thanks, using these time formats is a good point!