HI All
I have a lookup table which is populated by a scheduled search once everyday.
The lookup table looks like below
Tickets, Cases, Events, _time
10, 11, 45, 2019-11-01
14, 15, 79, 2019-11-02
11, 22, 84, 2019-11-03
The query used to populate the lookup table is as below
<index> <base search>
| timechart span=1d count by actionItem
Here the actionItems are Tickets, Cases, Events
All this is fine, lookup is created, lookup is populating and fetching etc.
But when I want to query the lookup table based on time, I am unable to do so.
I tried using the below queries but none of them worked.
| inputlookup lookup.csv
| where strptime(_time, "%Y-%m-%d") >= "2019-11-01"
| table *
| inputlookup lookup.csv
| search _time >= "2019-11-01"
| table *
| inputlookup cases_and_events.csv
| search earliest="11/01/2019:00:00:00" latest="11/04/2019:00:00:00"
| table *
Can someone please point me to the right keywords to fetch the details based on _time.
I understand that it seems the confusion is created because I have the column name as _time in thelookup csv
This is because the initial look up load query was created using timechart.
Thanks
... View more