<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to search from custom time field? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-from-custom-time-field/m-p/601155#M209230</link>
    <description>&lt;P&gt;Thanks you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/211432"&gt;@jamie00171&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I tried your solution with below query, I think am getting expected results. Thanks agian!&lt;/P&gt;&lt;P&gt;| eval etime=(strftime(strptime(last_found,"%Y-%m-%dT%H:%M:%S.%Q%Z"),"%s"))&lt;BR /&gt;| eval seven_days_ago=relative_time(now(), "-7d")&lt;BR /&gt;| where etime &amp;gt; seven_days_ago&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jun 2022 09:22:01 GMT</pubDate>
    <dc:creator>kpavan</dc:creator>
    <dc:date>2022-06-09T09:22:01Z</dc:date>
    <item>
      <title>How to search from custom time field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-from-custom-time-field/m-p/601054#M209207</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I have logs which is from db_inputs/custom_script where owner not indexing custom time field as _time and they are importing all data every day without incremental.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So i need to find assets which is last 7days with custom time field&lt;/P&gt;
&lt;P&gt;custom time field is last_found,&lt;/P&gt;
&lt;P&gt;&lt;A href="https://internal.paypalinc.com/splunkgp/en-US/app/search-securityreporting/search?q=search%20index%3Dpp_security_tenable_automation%20sourcetype%3D%22tenable%3Aio%3Aassets%22%20%0A%7C%20eval%20filterdate%3D(strftime(strptime(last_found%2C%22%25Y-%25m-%25dT%25H%3A%25M%3A%25S.%25Q%25Z%22)%2C%22%25Y-%25m-%25d%20%25H%3A%25M%3A%25S%22))&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-7d%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1654705009.45373_15AEB5F8-BC76-42D8-BE8F-54512BD1CF43#" target="_blank" rel="noopener"&gt;2020-07-06T17:42:29.322Z&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://internal.paypalinc.com/splunkgp/en-US/app/search-securityreporting/search?q=search%20index%3Dpp_security_tenable_automation%20sourcetype%3D%22tenable%3Aio%3Aassets%22%20%0A%7C%20eval%20filterdate%3D(strftime(strptime(last_found%2C%22%25Y-%25m-%25dT%25H%3A%25M%3A%25S.%25Q%25Z%22)%2C%22%25Y-%25m-%25d%20%25H%3A%25M%3A%25S%22))&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-7d%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1654705009.45373_15AEB5F8-BC76-42D8-BE8F-54512BD1CF43#" target="_blank" rel="noopener"&gt;2020-01-06T17:42:29.322Z&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://internal.paypalinc.com/splunkgp/en-US/app/search-securityreporting/search?q=search%20index%3Dpp_security_tenable_automation%20sourcetype%3D%22tenable%3Aio%3Aassets%22%20%0A%7C%20eval%20filterdate%3D(strftime(strptime(last_found%2C%22%25Y-%25m-%25dT%25H%3A%25M%3A%25S.%25Q%25Z%22)%2C%22%25Y-%25m-%25d%20%25H%3A%25M%3A%25S%22))&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-7d%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1654705009.45373_15AEB5F8-BC76-42D8-BE8F-54512BD1CF43#" target="_blank" rel="noopener"&gt;2020-01-05T17:42:29.322Z&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://internal.paypalinc.com/splunkgp/en-US/app/search-securityreporting/search?q=search%20index%3Dpp_security_tenable_automation%20sourcetype%3D%22tenable%3Aio%3Aassets%22%20%0A%7C%20eval%20filterdate%3D(strftime(strptime(last_found%2C%22%25Y-%25m-%25dT%25H%3A%25M%3A%25S.%25Q%25Z%22)%2C%22%25Y-%25m-%25d%20%25H%3A%25M%3A%25S%22))&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-7d%40h&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1654705009.45373_15AEB5F8-BC76-42D8-BE8F-54512BD1CF43#" target="_blank" rel="noopener"&gt;2020-01-04T17:42:29.322Z&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;from these date&amp;amp;time how can i search assets which is only last 7days from last_found custom time field. Please help on the query that would be great help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 16:39:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-from-custom-time-field/m-p/601054#M209207</guid>
      <dc:creator>kpavan</dc:creator>
      <dc:date>2022-06-08T16:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to search from custom time field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-from-custom-time-field/m-p/601058#M209209</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49826"&gt;@kpavan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;You could use strptime to convert last_found to an epoch timestamp:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SCS/current/SearchReference/DateandTimeFunctions#strptime" target="_blank"&gt;https://docs.splunk.com/Documentation/SCS/current/SearchReference/DateandTimeFunctions#strptime&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Then do something like:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;| eval seven_days_ago=relative_time(now(), "-7d")&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Then search for events where last_found &amp;gt; seven_days_ago&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jamie&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 17:15:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-from-custom-time-field/m-p/601058#M209209</guid>
      <dc:creator>jamie00171</dc:creator>
      <dc:date>2022-06-08T17:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to search from custom time field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-from-custom-time-field/m-p/601155#M209230</link>
      <description>&lt;P&gt;Thanks you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/211432"&gt;@jamie00171&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I tried your solution with below query, I think am getting expected results. Thanks agian!&lt;/P&gt;&lt;P&gt;| eval etime=(strftime(strptime(last_found,"%Y-%m-%dT%H:%M:%S.%Q%Z"),"%s"))&lt;BR /&gt;| eval seven_days_ago=relative_time(now(), "-7d")&lt;BR /&gt;| where etime &amp;gt; seven_days_ago&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 09:22:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-from-custom-time-field/m-p/601155#M209230</guid>
      <dc:creator>kpavan</dc:creator>
      <dc:date>2022-06-09T09:22:01Z</dc:date>
    </item>
  </channel>
</rss>

