<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Find Latency in Days in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Find-Latency-in-Days/m-p/741807#M12415</link>
    <description>&lt;P&gt;Usually when you are using 1000 with divider and/or multiplier, there have done conversion between ms and s and vice versa.&lt;BR /&gt;86400 is 24h in seconds&lt;/P&gt;&lt;P&gt;It's hard to say more without seeing your data/values on those fields.&lt;/P&gt;&lt;P&gt;One way to see it is use&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval latencyInDays = tostring(latencyInSeconds, "duration")&lt;/LI-CODE&gt;&lt;P&gt;and if you want to just show it in screen but keep value still in seconds just replace eval with fieldformat.&amp;nbsp;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Fri, 14 Mar 2025 14:06:49 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2025-03-14T14:06:49Z</dc:date>
    <item>
      <title>Find Latency in Days</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Find-Latency-in-Days/m-p/741806#M12414</link>
      <description>&lt;P&gt;I have a splunk where one of the eval method as part of main splunk query is as below.Iam not sure why SnapshotTimestamp is divided by 1000 but I presume it could be done to convert it to seconds.Sorry am a newbie&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval snapshot_processed = strftime(SnapshotTimestamp/1000, "%Y-%m-%d %H:%M:%S")&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Iam trying to find the # of days clasped between "snapshot_processed" and today. I tried to modify the splunk as below and then try to view the table for "latencyInDays".However it does not return any value.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval nowstring=now()
| eval latencyInDays=(nowstring-snapshot_processed)/86400&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;What am I missing?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 13:50:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Find-Latency-in-Days/m-p/741806#M12414</guid>
      <dc:creator>bmer</dc:creator>
      <dc:date>2025-03-14T13:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: Find Latency in Days</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Find-Latency-in-Days/m-p/741807#M12415</link>
      <description>&lt;P&gt;Usually when you are using 1000 with divider and/or multiplier, there have done conversion between ms and s and vice versa.&lt;BR /&gt;86400 is 24h in seconds&lt;/P&gt;&lt;P&gt;It's hard to say more without seeing your data/values on those fields.&lt;/P&gt;&lt;P&gt;One way to see it is use&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval latencyInDays = tostring(latencyInSeconds, "duration")&lt;/LI-CODE&gt;&lt;P&gt;and if you want to just show it in screen but keep value still in seconds just replace eval with fieldformat.&amp;nbsp;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 14:06:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Find-Latency-in-Days/m-p/741807#M12415</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-03-14T14:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: Find Latency in Days</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Find-Latency-in-Days/m-p/741808#M12416</link>
      <description>&lt;LI-CODE lang="markup"&gt;| eval duration = tostring(diff, "duration")&lt;/LI-CODE&gt;&lt;P&gt;This will output Days &amp;amp; Clock type output.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 14:03:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Find-Latency-in-Days/m-p/741808#M12416</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2025-03-14T14:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: Find Latency in Days</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Find-Latency-in-Days/m-p/741809#M12417</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242590"&gt;@bmer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is your&amp;nbsp;SnapshotTimestamp in milliseconds? Im assuming so because you're dividing by 1000.&lt;/P&gt;&lt;P&gt;You should be able to do this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval latencyInDays=floor((now()-(SnapshotTimestamp/1000)) / 86400)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Here is a full example to test with:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval SnapshotTimestamp=1741788339000
| eval latencyInDays=floor((now()-(SnapshotTimestamp/1000)) / 86400)&lt;/LI-CODE&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 14:07:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Find-Latency-in-Days/m-p/741809#M12417</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-14T14:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Find Latency in Days</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Find-Latency-in-Days/m-p/741811#M12418</link>
      <description>&lt;P&gt;The query is mixing strings (snapshot_processed) with integers (nowstring), which Splunk cannot do.&amp;nbsp; Try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval latencyInDays=(now() - SnapshotTimestamp/1000)/86400&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 14 Mar 2025 14:10:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Find-Latency-in-Days/m-p/741811#M12418</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-03-14T14:10:51Z</dc:date>
    </item>
  </channel>
</rss>

