Issue with timestamp_range_start and timestamp_range_end Dates in XSOAR Elasticsearch Integration Command

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Issue with timestamp_range_start and timestamp_range_end Dates in XSOAR Elasticsearch Integration Command

L1 Bithead
Problem Description:
The date filtering functionality for start and end dates in the Elasticsearch search command on XSOAR does not seem to be working correctly. The command used is as follows:!es-search index="index-runtime-evts" query="queryTest" timestamp_range_start="-2y" timestamp_range_end="now"I also tried entering a specific timestamp, such as 2023-10-02T00:00:00Z in the timestamp_range_start field, but I keep getting an empty response.Additional Details:
  • If I omit timestamp_range_start and timestamp_range_end in the War Room/playbook, I can retrieve all logs from the specified index (index-runtime-evts).
  • However, the goal is to filter the logs based on a 7-day range rather than retrieving the entire index history.
1 REPLY 1

L1 Bithead

Hello,

 

I use two formats for my !es-search tasks:
1. exact time in format 2024-11-06T14:48:47.149000+00:00
2. key words like in Kibana filtering through time, like "24 hours ago", "3 months ago", etc

 

Hope this helps.

  • 268 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!