<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Another time/date/string query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Another-time-date-string-query/m-p/334633#M165495</link>
    <description>&lt;P&gt;Hi&lt;BR /&gt;
you don't convert &lt;CODE&gt;time&lt;/CODE&gt; in human readable but in epochtime using &lt;CODE&gt;time=strptime(lastlogondate,"%d/%m/%Y %H:%M")&lt;/CODE&gt;&lt;BR /&gt;
if you want a human readable format you have to use &lt;CODE&gt;strftime&lt;/CODE&gt;.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 26 Oct 2017 08:01:59 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2017-10-26T08:01:59Z</dc:date>
    <item>
      <title>Another time/date/string query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Another-time-date-string-query/m-p/334632#M165494</link>
      <description>&lt;P&gt;Hi All, &lt;/P&gt;

&lt;P&gt;I am recently new to SPLUNK and trying to identify a way of doing some time differences.  I have done an export for the enabled devices in AD and their last logon times.  An example of a result is&lt;/P&gt;

&lt;P&gt;HOSTNUMBER1,HOSTNUMBER1.domain.com,Windows Server 2008, 26/10/2017 7:40&lt;/P&gt;

&lt;P&gt;From my list I have strung together the following query&lt;/P&gt;

&lt;P&gt;index=adlastlogondate AND sourcetype=csv | eval currenttime=strftime(now(),"%d/%m/%Y %H:%M") | eval time=strptime(lastlogondate,"%d/%m/%Y %H:%M") eval timedifference=lastlogontime-today | table hostname time lastlogondate currenttime timedifference | sort time&lt;/P&gt;

&lt;P&gt;This generates the following result (NOTE: using "|" to denote columns in the table).  Note I get no time difference (which is likely due to this bring a string)&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Hostname             | time                                | lastlogondate         | currenttime            | timedifference&lt;/P&gt;

&lt;P&gt;HOSTNUMBER1   | 12114214569.000000 | 25/10/2017 01:00   | 26/10/2017 15:16  |    &lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;I tried running this to convert the string into an epoch time(?) to try this but I get the same result&lt;/P&gt;

&lt;P&gt;index=adlastlogondate AND sourcetype=csv | eval currenttime=strftime(now(),"%d/%m/%Y %H:%M") | eval time=strptime(lastlogondate,"%d/%m/%Y %H:%M") | convert ctime(time) AS lastlogontime | convert ctime(currenttime) AS today |eval timedifference=lastlogontime-today | table hostname time lastlogondate currenttime timedifference | sort time&lt;/P&gt;

&lt;P&gt;Where am I going wrong?  &lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 07:22:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Another-time-date-string-query/m-p/334632#M165494</guid>
      <dc:creator>willadams</dc:creator>
      <dc:date>2017-10-26T07:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Another time/date/string query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Another-time-date-string-query/m-p/334633#M165495</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
you don't convert &lt;CODE&gt;time&lt;/CODE&gt; in human readable but in epochtime using &lt;CODE&gt;time=strptime(lastlogondate,"%d/%m/%Y %H:%M")&lt;/CODE&gt;&lt;BR /&gt;
if you want a human readable format you have to use &lt;CODE&gt;strftime&lt;/CODE&gt;.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 08:01:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Another-time-date-string-query/m-p/334633#M165495</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-10-26T08:01:59Z</dc:date>
    </item>
  </channel>
</rss>

