<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic regex help, extract time and convert to epoch and show only if epoch time is within 24 hours ago in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/regex-help-extract-time-and-convert-to-epoch-and-show-only-if/m-p/691103#M235358</link>
    <description>&lt;P&gt;hi, i currently have this data and i would like to see if i can extract the date and time and see if it can display the LINE if its within the last 24 hours.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;example: current time June 19&amp;nbsp;&lt;/P&gt;&lt;P&gt;result should be:&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;drwxrwxrwx 2 root root 4.0K Jun 19 06:05 crashinfo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---------------------- DATA START below -----------------------&lt;/P&gt;&lt;P&gt;/opt/var.dp2/cores/:&lt;BR /&gt;total 4.0K&lt;BR /&gt;drwxrwxrwx 2 root root 4.0K Jun 19 06:05 crashinfo&lt;/P&gt;&lt;P&gt;/opt/var.dp2/cores/crashinfo:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;/var/cores/:&lt;BR /&gt;total 8.0K&lt;BR /&gt;drwxrwxrwx 2 root root 4.0K May 28 06:05 crashinfo&lt;BR /&gt;drwxr-xr-x 2 root root 4.0K May 28 06:05 crashjobs&lt;/P&gt;&lt;P&gt;/var/cores/crashinfo:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;/var/cores/crashjobs:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;/opt/panlogs/cores/:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;/opt/var.cp/cores/:&lt;BR /&gt;total 4.0K&lt;BR /&gt;drwxr-xr-x 2 root root 4.0K May 28 06:06 crashjobs&lt;/P&gt;&lt;P&gt;/opt/var.cp/cores/crashjobs:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;/opt/var.dp1/cores/:&lt;BR /&gt;total 8.0K&lt;BR /&gt;drwxrwxrwx 2 root root 4.0K May 28 06:05 crashinfo&lt;BR /&gt;drwxr-xr-x 2 root root 4.0K May 28 06:07 crashjobs&lt;/P&gt;&lt;P&gt;/opt/var.dp1/cores/crashinfo:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;/opt/var.dp1/cores/crashjobs:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;/opt/var.dp0/cores/:&lt;BR /&gt;total 8.0K&lt;BR /&gt;drwxrwxrwx 2 root root 4.0K May 28 06:05 crashinfo&lt;BR /&gt;drwxr-xr-x 2 root root 4.0K May 28 06:07 crashjobs&lt;/P&gt;&lt;P&gt;/opt/var.dp0/cores/crashinfo:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;/opt/var.dp0/cores/crashjobs:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---------------------- DATA END above -----------------------&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jun 2024 14:18:56 GMT</pubDate>
    <dc:creator>thaghost99</dc:creator>
    <dc:date>2024-06-19T14:18:56Z</dc:date>
    <item>
      <title>regex help, extract time and convert to epoch and show only if epoch time is within 24 hours ago</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-extract-time-and-convert-to-epoch-and-show-only-if/m-p/691103#M235358</link>
      <description>&lt;P&gt;hi, i currently have this data and i would like to see if i can extract the date and time and see if it can display the LINE if its within the last 24 hours.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;example: current time June 19&amp;nbsp;&lt;/P&gt;&lt;P&gt;result should be:&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;drwxrwxrwx 2 root root 4.0K Jun 19 06:05 crashinfo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---------------------- DATA START below -----------------------&lt;/P&gt;&lt;P&gt;/opt/var.dp2/cores/:&lt;BR /&gt;total 4.0K&lt;BR /&gt;drwxrwxrwx 2 root root 4.0K Jun 19 06:05 crashinfo&lt;/P&gt;&lt;P&gt;/opt/var.dp2/cores/crashinfo:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;/var/cores/:&lt;BR /&gt;total 8.0K&lt;BR /&gt;drwxrwxrwx 2 root root 4.0K May 28 06:05 crashinfo&lt;BR /&gt;drwxr-xr-x 2 root root 4.0K May 28 06:05 crashjobs&lt;/P&gt;&lt;P&gt;/var/cores/crashinfo:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;/var/cores/crashjobs:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;/opt/panlogs/cores/:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;/opt/var.cp/cores/:&lt;BR /&gt;total 4.0K&lt;BR /&gt;drwxr-xr-x 2 root root 4.0K May 28 06:06 crashjobs&lt;/P&gt;&lt;P&gt;/opt/var.cp/cores/crashjobs:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;/opt/var.dp1/cores/:&lt;BR /&gt;total 8.0K&lt;BR /&gt;drwxrwxrwx 2 root root 4.0K May 28 06:05 crashinfo&lt;BR /&gt;drwxr-xr-x 2 root root 4.0K May 28 06:07 crashjobs&lt;/P&gt;&lt;P&gt;/opt/var.dp1/cores/crashinfo:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;/opt/var.dp1/cores/crashjobs:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;/opt/var.dp0/cores/:&lt;BR /&gt;total 8.0K&lt;BR /&gt;drwxrwxrwx 2 root root 4.0K May 28 06:05 crashinfo&lt;BR /&gt;drwxr-xr-x 2 root root 4.0K May 28 06:07 crashjobs&lt;/P&gt;&lt;P&gt;/opt/var.dp0/cores/crashinfo:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;/opt/var.dp0/cores/crashjobs:&lt;BR /&gt;total 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---------------------- DATA END above -----------------------&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2024 14:18:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-extract-time-and-convert-to-epoch-and-show-only-if/m-p/691103#M235358</guid>
      <dc:creator>thaghost99</dc:creator>
      <dc:date>2024-06-19T14:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: regex help, extract time and convert to epoch and show only if epoch time is within 24 hours ago</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-extract-time-and-convert-to-epoch-and-show-only-if/m-p/691108#M235361</link>
      <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex max_match=0 "(?m)^(\S+ ){5}(?&amp;lt;datetimefile&amp;gt;\w+ +\d+\s+\d+:\d+\s+\S+)$"
| mvexpand datetimefile
| eval timestamp=strptime(datetimefile,"%b %d %H:%M")
| where now()-timestamp &amp;lt; 24*60*60&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 19 Jun 2024 14:46:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-extract-time-and-convert-to-epoch-and-show-only-if/m-p/691108#M235361</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-06-19T14:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: regex help, extract time and convert to epoch and show only if epoch time is within 24 hours ago</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-extract-time-and-convert-to-epoch-and-show-only-if/m-p/691110#M235362</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;``` Parse the date ```
| rex "\s(?&amp;lt;date&amp;gt;\w{3}\s\d{1,2})\s"
``` Convert the date into epoch form ```
| eval epoch=strptime(date, "%b %d")
``` See if the date falls in the last 24 hours ```
| where epoch &amp;gt; relative_time(now(), "-24h")&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 19 Jun 2024 15:01:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-extract-time-and-convert-to-epoch-and-show-only-if/m-p/691110#M235362</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-06-19T15:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: regex help, extract time and convert to epoch and show only if epoch time is within 24 hours ago</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-extract-time-and-convert-to-epoch-and-show-only-if/m-p/691111#M235363</link>
      <description>&lt;P&gt;thank you very much. it works.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2024 15:38:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-extract-time-and-convert-to-epoch-and-show-only-if/m-p/691111#M235363</guid>
      <dc:creator>thaghost99</dc:creator>
      <dc:date>2024-06-19T15:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: regex help, extract time and convert to epoch and show only if epoch time is within 24 hours ago</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-extract-time-and-convert-to-epoch-and-show-only-if/m-p/691459#M235447</link>
      <description>&lt;P&gt;if it shows no results, how can i make it so that the value of that 'epoch' value = OK versus 'Not Ok'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 14:40:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-extract-time-and-convert-to-epoch-and-show-only-if/m-p/691459#M235447</guid>
      <dc:creator>thaghost99</dc:creator>
      <dc:date>2024-06-24T14:40:08Z</dc:date>
    </item>
  </channel>
</rss>

