<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fix column name and evalute times in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-column-name-and-evaluate-times/m-p/624609#M217140</link>
    <description>&lt;P&gt;Use rex to extract the two timestamps then use strptime to convert them into epoch (integer) form.&amp;nbsp; Then you can compare then to see how far apart they are.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults | eval _raw="2022-12-16 21:30:17.689, TO_CHAR(schema.function(MAX(columnA)),'MM-DD-YYHH24:MI')=\"12-16-22 16:29\""
```Above creates demo data.  Delete IRL```
| rex "(?&amp;lt;time1&amp;gt;^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d.\d\d\d)"
| rex "(?&amp;lt;time2&amp;gt;\d\d-\d\d-\d\d \d\d:\d\d\\\")"
| eval diffsecs = strptime(time1, "%Y-%m-%d %H:%M:%S.%3N") - strptime(time2, "%m-%d-%y %H:%M")
| eval old=if(abs(diffsecs) &amp;gt; (15*60),1 ,0)&lt;/LI-CODE&gt;</description>
    <pubDate>Fri, 16 Dec 2022 22:03:46 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-12-16T22:03:46Z</dc:date>
    <item>
      <title>How to fix column name and evaluate times?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-column-name-and-evaluate-times/m-p/624608#M217139</link>
      <description>&lt;P&gt;I have a dbquery ouput that looks like the below, unfortunately i cant update the actual database query to make it more readable...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;2022-12-16&lt;/SPAN&gt; &lt;SPAN class=""&gt;21:30:17.689&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;TO_CHAR&lt;/SPAN&gt;&lt;SPAN&gt;(schema.function&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;MAX&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;columnA&lt;/SPAN&gt;&lt;SPAN&gt;)),'&lt;/SPAN&gt;&lt;SPAN class=""&gt;MM-DD-YYHH24:MI&lt;/SPAN&gt;&lt;SPAN&gt;')&lt;/SPAN&gt;&lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;12-16-22&lt;/SPAN&gt; &lt;SPAN class=""&gt;16:29"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;I am trying to whether time the 2 times&amp;nbsp; at the begining and end of the results are within 15 mins of each other. I have tried renaming the column from the long stupid string but i cant get that working using the rename function.&amp;nbsp; does anyone have any ideas how to rename (or if i even need to) and then evaluate whether the times are within 15 mins of each other?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;the query i ran to get the above is just &amp;lt;index="abc"&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 23:00:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-column-name-and-evaluate-times/m-p/624608#M217139</guid>
      <dc:creator>HelloItsMe76</dc:creator>
      <dc:date>2022-12-16T23:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: Fix column name and evalute times</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-column-name-and-evaluate-times/m-p/624609#M217140</link>
      <description>&lt;P&gt;Use rex to extract the two timestamps then use strptime to convert them into epoch (integer) form.&amp;nbsp; Then you can compare then to see how far apart they are.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults | eval _raw="2022-12-16 21:30:17.689, TO_CHAR(schema.function(MAX(columnA)),'MM-DD-YYHH24:MI')=\"12-16-22 16:29\""
```Above creates demo data.  Delete IRL```
| rex "(?&amp;lt;time1&amp;gt;^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d.\d\d\d)"
| rex "(?&amp;lt;time2&amp;gt;\d\d-\d\d-\d\d \d\d:\d\d\\\")"
| eval diffsecs = strptime(time1, "%Y-%m-%d %H:%M:%S.%3N") - strptime(time2, "%m-%d-%y %H:%M")
| eval old=if(abs(diffsecs) &amp;gt; (15*60),1 ,0)&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 16 Dec 2022 22:03:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-column-name-and-evaluate-times/m-p/624609#M217140</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-12-16T22:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: Fix column name and evalute times</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-column-name-and-evaluate-times/m-p/624738#M217178</link>
      <description>&lt;P&gt;this is beautiful. thanks so much. it works perfectly.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 15:53:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-column-name-and-evaluate-times/m-p/624738#M217178</guid>
      <dc:creator>HelloItsMe76</dc:creator>
      <dc:date>2022-12-19T15:53:23Z</dc:date>
    </item>
  </channel>
</rss>

