I am calculating monthly averages and have an issue where on a single day in October there was an error in the data. I would like to remove this single date and time range (Oct 12th 00:00-04:00) from the overall monthly average but don't want to impact future month calculations.
I run the following command for year to date to get monthly average -
index=xyz sourcetype=zyx | timechart span=1month avg(VALUE)
When I add NOT earliest="10/12/2019:00:00:00" latest="10/12/2019:04:00:00" to my base search it only provides that date. I tried adding brackets etc and it is not working.
Any suggestions would be appreciated!
Thanks!
You could try where
with timestamp boundaries. For example, this excludes 10/31/2019 09:00 - 10:00:
... | where _time<1572537600 OR _time>1572541200
You could try where
with timestamp boundaries. For example, this excludes 10/31/2019 09:00 - 10:00:
... | where _time<1572537600 OR _time>1572541200
That works, thank you !!!