[FEATURE]support earliest/latest
date-time functions
#3173
Labels
catch-all acknowledged
Marks issues caught in catch-all triage for searchability
enhancement
New feature or request
PPL
Piped processing language
Is your feature request related to a problem?
As a PPL query syntax for easily supporting predefined simple time ranges such as:
earliest week
,latest day
,latest month
,earliest hour
.Supporting for the predefined time units:
s
m
h
d
w
mnt
qrt
yr
What solution would you like?
source = logs | where status > 200 AND (earliest=-24h AND latest<@d)
source = logs | where status > 200 AND (earliest=-5d@w1 AND latest=@w6)
source = logs | where status > 200 AND (earliest='2023-11-15:20:00:00' AND latest='2023-11-22:20:00:00')
The text was updated successfully, but these errors were encountered: