index=windows sourctype=bla
EventCode=g host=abc user=cvb NOT [
search index=email |table _time,host
|fields _time, host]
I have to schedule a search similar to above to run every 10m, but I want the sub-search to look for events 5 minutes before to the info_min_time.
I tried the following but doesn't seem to help.
earliest=$info_min_time$ latest=$info_max_time$index=windows sourctype=bla EventCode=g host=abc user=cvb NOT
[ search index=email
||eval earliest = relative_time($info_min_time$, "-5M")
|table _time,host
|fields _time, host]
Is there any way to achieve this?
This one got passed up, but here's the answer:
index=windows sourctype=bla EventCode=g host=abc user=cvb NOT [
| search index=email earliest=-5m
| table _time,host
| fields _time, host]