What I've got, maybe I went wrong with this but I'm not quite sure on how to finish it.
My token that's passed into this is called "timevalue", which will be an input like i said above (1/1/18 2:00:20.000 PM). This is taken from another dashboard result.
| from datamodel:"Apps"."All_Apps" | search source="Access - Apps - Rule" (This is the dataset I'm searching in)
| eval timeformat1="$timevalue$"
| eval timeformat2=strftime(strptime(timeformat1, "%x %I:%M:%S.%3Q %p"), "%FT%H:%M:%S.%3Q")
What would I add onto this now that I've converted the time I had to the _time value to search it?
I want to search for the events that happened at that exact time. (This is how we're correlating two events to eachother since if they got into this datamodel they're related, but the only data we have to search for what we want is the time value.)
... View more