Ex: | where first_seen<"24h" or where first_seen="-1d" this is what I used but obviously it's wrong.
You would need to make use of relative_time function in there.
If first_seen is in epoch format, then try like this
..| where first_seen>=relative_time(now(),"-24h")
If it's not in epoch, need to convert it to epoch to compare
..| where strptime(first_seen,"<<TimeFormatHere>>") >=relative_time(now(),"-24h")
You would need to make use of relative_time function in there.
If first_seen is in epoch format, then try like this
..| where first_seen>=relative_time(now(),"-24h")
If it's not in epoch, need to convert it to epoch to compare
..| where strptime(first_seen,"<<TimeFormatHere>>") >=relative_time(now(),"-24h")
Your are the man with the juice!!!