<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Compare usual time to Epoch time in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570078#M10279</link>
    <description>&lt;P&gt;_time looks like this&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2021-10-07 08:28:04.211&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;epoch column&amp;nbsp; is blank&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Oct 2021 15:04:25 GMT</pubDate>
    <dc:creator>luckyman80</dc:creator>
    <dc:date>2021-10-07T15:04:25Z</dc:date>
    <item>
      <title>Compare usual time to Epoch time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570017#M10265</link>
      <description>&lt;P&gt;Hi Experts! ,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Wondered if there was a way of doing this. I have a need to compare a timestamp of a log to an EPOCH time also on the same log line and show the Diff&lt;/P&gt;&lt;P&gt;Example&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2021-10-05 04:49:10.138&lt;/STRONG&gt; [pool-1-thread-1] INFO order - [Pool]Book={inst=example,1=[],2=[feed-|time=&lt;STRONG&gt;1633427347600000000}&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Manually looking the difference is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2021-10-05 04:49:10.138 -(Standard time)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2021-10-05 04:49:07.600 -(EPOCH time)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Difference 2.54 seconds&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 09:56:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570017#M10265</guid>
      <dc:creator>luckyman80</dc:creator>
      <dc:date>2021-10-07T09:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: Compare usual time to Epoch time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570031#M10268</link>
      <description>&lt;P&gt;Is your "standard" time already extracted as _time?&lt;/P&gt;&lt;P&gt;Your EPOCH time looks like it might be in nano-seconds, so try&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval diff=_time-(epoch/1000000000)&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 07 Oct 2021 10:43:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570031#M10268</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-10-07T10:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: Compare usual time to Epoch time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570036#M10269</link>
      <description>&lt;P&gt;Hi! Thanks for the quick response!&amp;nbsp; I haven't Extracted time yet (not sure how to do that) also how do I display it after ? sorry for all the questions&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 10:55:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570036#M10269</guid>
      <dc:creator>luckyman80</dc:creator>
      <dc:date>2021-10-07T10:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: Compare usual time to Epoch time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570038#M10271</link>
      <description>&lt;P&gt;You may find it has already been extracted for you when the events were indexed. What fields do you have extracted?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 10:58:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570038#M10271</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-10-07T10:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: Compare usual time to Epoch time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570045#M10273</link>
      <description>&lt;P&gt;Apols if im being stupid . I tried&amp;nbsp;&lt;/P&gt;&lt;P&gt;| eval diff=_time-(epoch/1000000000)|table diff&lt;/P&gt;&lt;P&gt;but dont see anything&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 12:10:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570045#M10273</guid>
      <dc:creator>luckyman80</dc:creator>
      <dc:date>2021-10-07T12:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: Compare usual time to Epoch time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570049#M10274</link>
      <description>&lt;P&gt;What do you get if you just do&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;&amp;lt;your search&amp;gt;&amp;gt;
| table _time epoch&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 07 Oct 2021 12:17:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570049#M10274</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-10-07T12:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: Compare usual time to Epoch time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570078#M10279</link>
      <description>&lt;P&gt;_time looks like this&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2021-10-07 08:28:04.211&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;epoch column&amp;nbsp; is blank&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 15:04:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570078#M10279</guid>
      <dc:creator>luckyman80</dc:creator>
      <dc:date>2021-10-07T15:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Compare usual time to Epoch time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570084#M10280</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Your base search| eva diff=_time-time | table diff&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 07 Oct 2021 15:56:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570084#M10280</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2021-10-07T15:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Compare usual time to Epoch time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570087#M10282</link>
      <description>&lt;LI-SPOILER&gt;i did try that .. now I get&amp;nbsp;&lt;BR /&gt;_time as&amp;nbsp;2021-10-07 12:30:03.839&lt;BR /&gt;&lt;BR /&gt;and diff as -1633624103220375800.000&lt;BR /&gt;&lt;BR /&gt;&lt;/LI-SPOILER&gt;</description>
      <pubDate>Thu, 07 Oct 2021 16:31:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570087#M10282</guid>
      <dc:creator>luckyman80</dc:creator>
      <dc:date>2021-10-07T16:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: Compare usual time to Epoch time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570090#M10283</link>
      <description>&lt;P&gt;OK extract epoch like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "time=(?&amp;lt;epoch&amp;gt;\d*)"&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 07 Oct 2021 16:52:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570090#M10283</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-10-07T16:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: Compare usual time to Epoch time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570105#M10284</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Your base search | eval diff=abs(_time-(time/1000000000))&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 18:34:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570105#M10284</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2021-10-07T18:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: Compare usual time to Epoch time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570135#M10286</link>
      <description>&lt;P&gt;thank you ! worked great&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 20:06:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Compare-usual-time-to-Epoch-time/m-p/570135#M10286</guid>
      <dc:creator>luckyman80</dc:creator>
      <dc:date>2021-10-07T20:06:28Z</dc:date>
    </item>
  </channel>
</rss>

