<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rex and time conversion in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/584168#M203425</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;, Thanks! it worked&lt;/P&gt;</description>
    <pubDate>Tue, 08 Feb 2022 20:20:30 GMT</pubDate>
    <dc:creator>bsanjee</dc:creator>
    <dc:date>2022-02-08T20:20:30Z</dc:date>
    <item>
      <title>How to extract startTime using query and then convert the extracted startTime- which is in GMT to PST?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/583796#M203304</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;
&lt;P&gt;Below is my sample event,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;2021-02-06&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;15:30:03&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;production.INFO:&lt;/SPAN&gt;&lt;SPAN&gt; {"&lt;/SPAN&gt;&lt;SPAN class=""&gt;uri&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;https:\/\/platform.ringcentral.com\/restapi\/v1.0\/account\/5706\/call-log\/SU7GHYajgzUA&lt;/SPAN&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;SPAN class=""&gt;view=Simple&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;id&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;SU7GHYaeMpjgzUA&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;sessionId&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;886240004&lt;/SPAN&gt;&lt;SPAN&gt;",&lt;STRONG&gt;"&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;startTime&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;"&lt;SPAN class=""&gt;2022-02-04T07:27:31-08:00&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;"&lt;/STRONG&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;duration&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:36&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;type&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Voice&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;internalType&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;TollFreeNumber&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;direction&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Inbound&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;action&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Phone&lt;/SPAN&gt; &lt;SPAN class=""&gt;Call&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;result&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Rejected&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;to&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;phoneNumber&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"+&lt;/SPAN&gt;&lt;SPAN class=""&gt;18558&lt;/SPAN&gt;&lt;SPAN&gt;"},"&lt;/SPAN&gt;&lt;SPAN class=""&gt;from&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;EAR&lt;/SPAN&gt; &lt;SPAN class=""&gt;NOS&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;phoneNumber&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"+&lt;/SPAN&gt;&lt;SPAN class=""&gt;1509&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;location&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Spokane&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;WA&lt;/SPAN&gt;&lt;SPAN&gt;"},"&lt;/SPAN&gt;&lt;SPAN class=""&gt;telephonySessionId&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;s-a0d16c80326f9z135c880000&lt;/SPAN&gt;&lt;SPAN&gt;"}&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;1. I have to extract startTime using query&lt;/P&gt;
&lt;P&gt;2. I have to convert the extracted startTime which is in GMT to PST, again using query&lt;/P&gt;
&lt;P&gt;I want to do 1 and 2 in the same query.&lt;/P&gt;
&lt;P&gt;How to do this?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 03:23:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/583796#M203304</guid>
      <dc:creator>bsanjee</dc:creator>
      <dc:date>2022-02-10T03:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Rex and time conversion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/583799#M203305</link>
      <description>&lt;P&gt;It would help to know what you've tried already.&lt;/P&gt;&lt;P&gt;Use the rex command to extract the startTime field like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "startTime\":\"(?&amp;lt;startTime&amp;gt;[^\"]+)"&lt;/LI-CODE&gt;&lt;P&gt;There is no need to convert it to PST since it's already in PST.&amp;nbsp; The "-0800" means eight hours behind GMT, which is PST.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Feb 2022 00:58:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/583799#M203305</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-02-05T00:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Rex and time conversion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/583883#M203337</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;, thanks for the regex. I am also getting another set of events whose time is GMT. May I know how this can be achieved in the same. Query?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Feb 2022 23:11:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/583883#M203337</guid>
      <dc:creator>bsanjee</dc:creator>
      <dc:date>2022-02-06T23:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: Rex and time conversion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/583885#M203338</link>
      <description>&lt;P&gt;Extracting the same is the same.&amp;nbsp; Converting it to epoch form (so it can be manipulated) may be different, depending on the exact format.&amp;nbsp; Please share a sample GMT timestamp.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 00:54:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/583885#M203338</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-02-07T00:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: Rex and time conversion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/583888#M203339</link>
      <description>&lt;P&gt;Here is the sample event with time in GMT,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;2021-02-06&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;15:30:03&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;production.INFO:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;uri&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;https:\/\/platform.ringcentral.com\/restapi\/v1.0\/account\/5706\/call-log\/SU7GHYajgzUA&lt;/SPAN&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;SPAN class=""&gt;view=Simple&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;id&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;SU7GHYaeMpjgzUA&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;sessionId&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;886240004&lt;/SPAN&gt;&lt;SPAN&gt;",&lt;STRONG&gt;"&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;startTime&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;"2021-05-05T11:23:39.426Z&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;"&lt;/STRONG&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;duration&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:36&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;type&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Voice&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;internalType&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;TollFreeNumber&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;direction&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Inbound&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;action&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Phone&lt;/SPAN&gt; &lt;SPAN class=""&gt;Call&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;result&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Rejected&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;to&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;phoneNumber&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"+&lt;/SPAN&gt;&lt;SPAN class=""&gt;18558&lt;/SPAN&gt;&lt;SPAN&gt;"},"&lt;/SPAN&gt;&lt;SPAN class=""&gt;from&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;EAR&lt;/SPAN&gt;&lt;SPAN class=""&gt;NOS&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;phoneNumber&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"+&lt;/SPAN&gt;&lt;SPAN class=""&gt;1509&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;location&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Spokane&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;WA&lt;/SPAN&gt;&lt;SPAN&gt;"},"&lt;/SPAN&gt;&lt;SPAN class=""&gt;telephonySessionId&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;s-a0d16c80326f9z135c880000&lt;/SPAN&gt;&lt;SPAN&gt;"}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 03:41:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/583888#M203339</guid>
      <dc:creator>bsanjee</dc:creator>
      <dc:date>2022-02-07T03:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: Rex and time conversion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/583963#M203354</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;, This is the GMT timeformat that i need to convert.&amp;nbsp;&lt;SPAN&gt;2021-05-05T11:23:39.426Z&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 15:20:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/583963#M203354</guid>
      <dc:creator>bsanjee</dc:creator>
      <dc:date>2022-02-07T15:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: Rex and time conversion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/584003#M203372</link>
      <description>&lt;P&gt;As it turns out, those two timestamp formats are just different enough to need two different conversion strings.&amp;nbsp; It can be done in SPL like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval startTS = if(isnotnull(strptime(startTime,"%Y-%m-%d-T%H:%M:%S.%3N%Z"), strptime(startTime, "%Y-%m-%d-T%H:%M:%S.%3N%Z"), strptime(startTime, "%Y-%m-%d-T%H:%M:%S.%3N%z"))&lt;/LI-CODE&gt;&lt;P&gt;The if function test to see if the timestamp matches one of the formats and, if it does (isnotnull) then performs the conversion using that format; otherwise, the conversion uses the other format.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 18:49:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/584003#M203372</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-02-07T18:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: Rex and time conversion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/584018#M203380</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;, Please let me know how to convert time in GMT to PST using query if am receiving logs with only GMT time(ignore the other time format you are seeing in my first post). Do I have to subtract 8 hrs?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 20:22:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/584018#M203380</guid>
      <dc:creator>bsanjeeva</dc:creator>
      <dc:date>2022-02-07T20:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: Rex and time conversion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/584028#M203384</link>
      <description>&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;strptime&lt;/FONT&gt; function will convert the timestamp into GMT.&amp;nbsp; The &lt;FONT face="courier new,courier"&gt;strftime&lt;/FONT&gt; function will convert it into your selected time zone.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval displayTime = strftime(startTS, "%Y-%m-%d %H:%M:%S %Z")&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 07 Feb 2022 22:35:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/584028#M203384</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-02-07T22:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: Rex and time conversion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/584168#M203425</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;, Thanks! it worked&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 20:20:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-startTime-using-query-and-then-convert-the/m-p/584168#M203425</guid>
      <dc:creator>bsanjee</dc:creator>
      <dc:date>2022-02-08T20:20:30Z</dc:date>
    </item>
  </channel>
</rss>

