I am trying to visualize the deviation between a correlation rule's scheduled time and the time it was run.
went through the index=_internal sourcetype=scheduler
and found the scheduled time in Unix timestamp format.
How can I convert Unix format and compare it with _time for given values of savedsearch_name
and have a clear visualization (to present it for management)
your search
|eval my_time= _time
Hi, @mo_shahin
try this, and check my_time
. It is unnecessary to convert to Unix timestamp format.
and, Visualization....
index=_internal sourcetype=scheduler
| eval diff=_time - savedsearch_name
| table _time diff
try Line Chart