Hi IRHM73,
Try to remove
<search> </search>
and write only:
<searchTemplate>|rest /services/search/jobs
|search NOT (author="splunk-system-user" OR author="monitoring")
|search title!=""
|search author =$author$
|addtotals fieldname=duration *duration_secs
|convert rmunit(duration) as numSecs
|eval stringSecs=tostring(duration,"duration")
|eval stringSecs = replace(stringSecs,"(\d+)\:(\d+)\:(\d+)","\1h \2min \3s")
|rex field=stringSecs "\.(?<ms>\d{2})" | rex field=stringSecs "(?<myRest>.+)s\."
|eval stringSecs=myRest. "s " .ms. "ms"
|eval NoOfDays=floor((searchLatestTime-searchEarliestTime)/(3600*24))
|where NoOfDays>=90 |eval earliestTime=strptime(earliestTime, "%Y-%m-%dT%H:%M:%S")
|convert timeformat="%d/%b/%Y" ctime(earliestTime)
|eval latestTime=strptime(latestTime, "%Y-%m-%dT%H:%M:%S")
|convert timeformat="%d/%b/%Y" ctime(latestTime)
|eval daterange= "From: ".earliestTime.", To: ".latestTime
|makemv delim=", " daterange
|sort +author
|table author eai:acl.app title daterange NoOfDays stringSecs
|rename author as "Search Author", eai:acl.app as "App Used", title as "Query", daterange as "Query Date Range", NoOfDays as "Query Date Range (Days)", stringSecs as "Query Runtime"
</searchTemplate>
... View more