Guidelines for date and time searches

Prev Next

Note the following guidelines for date and time searches:

  • The date and time you type in the search bar must be enclosed in single or double quotation marks (for example, eventtime>"2022-04-07T01:10"). If you use a pivot option from a parsed field to add a date and time to the search, quotation marks may be automatically included. For details about pivot options, see the Helix Enterprise Product Guide.

  • A time cannot be searched without a preceding date.

  • A date or a date and time cannot be searched directly in TQL. The date or date and time must follow a timestamp field and operator in a search string.

  • To evaluate a query using time values located in another field, you must specify that field.