I followed the instructions on the blog post and could not get it to work. I have a time field within my logs as
year=2018 month=04 day=05 hour=20 event_count=100 . The event came in 2018-06-03 2000 . I want to use the time picker to select events by their year, month, day, hour time fields. NOT when they came in. I overrode _time as well. This is what I have in my source
index=index_1 OR index=index_2 category=mobile event_type=hive_events zone=aws
| eval _time=strptime(time,"%Y-%m-%d-%H:%M:%S")
| sort - _time
| addinfo
| where _time >= info_min_time AND (_time <= info_max_time OR info_max_time = "+Infinity")
| eval DateHour=year."-".month."-".day."-".hour
| eval Start_Time=strftime(info_min_time, "%Y-%m-%d-%H:00")
| eval End_Time=strftime(info_max_time, "%Y-%m-%d-%H:00")
| table DateHour _time Start_time info_min_time End_time info_max_time zone event_count
... View more