<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Strptime bug? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Strptime-bug/m-p/26580#M5148</link>
    <description>&lt;P&gt;Has anyone else noticed that strptime does not work in the following situation?&lt;/P&gt;

&lt;P&gt;VersionExpiry has a value of &lt;STRONG&gt;9999-01-01 00:00:00&lt;/STRONG&gt; (or with any year greater than 2999)&lt;/P&gt;

&lt;P&gt;eval VersionExpiryEpoch=strptime(VersionExpiry, "%Y-%m-%d %H:%M:%S")&lt;/P&gt;

&lt;P&gt;Field "VersionExpiryEpoch" is never created&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Does anyone have any workaround ideas to force Splunk in recognizing that existence may, in fact, continue past the year 2999? &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;The raw data Splunk is receiving is indicating that the version, as of this moment, does not have an expiration date... hence the year 9999.  I could, easily, hardcode it in the query that a value of 9999-01-01 00:00:00 means that the version is up to date, but I'd prefer that the function worked correctly.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Nov 2012 16:44:05 GMT</pubDate>
    <dc:creator>ARothman</dc:creator>
    <dc:date>2012-11-07T16:44:05Z</dc:date>
    <item>
      <title>Strptime bug?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Strptime-bug/m-p/26580#M5148</link>
      <description>&lt;P&gt;Has anyone else noticed that strptime does not work in the following situation?&lt;/P&gt;

&lt;P&gt;VersionExpiry has a value of &lt;STRONG&gt;9999-01-01 00:00:00&lt;/STRONG&gt; (or with any year greater than 2999)&lt;/P&gt;

&lt;P&gt;eval VersionExpiryEpoch=strptime(VersionExpiry, "%Y-%m-%d %H:%M:%S")&lt;/P&gt;

&lt;P&gt;Field "VersionExpiryEpoch" is never created&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Does anyone have any workaround ideas to force Splunk in recognizing that existence may, in fact, continue past the year 2999? &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;The raw data Splunk is receiving is indicating that the version, as of this moment, does not have an expiration date... hence the year 9999.  I could, easily, hardcode it in the query that a value of 9999-01-01 00:00:00 means that the version is up to date, but I'd prefer that the function worked correctly.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2012 16:44:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Strptime-bug/m-p/26580#M5148</guid>
      <dc:creator>ARothman</dc:creator>
      <dc:date>2012-11-07T16:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: Strptime bug?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Strptime-bug/m-p/26581#M5149</link>
      <description>&lt;P&gt;If you just need it to work on that specific far future date, then you could do something like this:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;search goes here | eval VersionExpiryEpoch = coalesce(strptime(VersionExpiry, "%Y-%m-%d %H:%M:%S"), 253370786400)&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 16:33:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Strptime-bug/m-p/26581#M5149</guid>
      <dc:creator>dart</dc:creator>
      <dc:date>2012-11-08T16:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: Strptime bug?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Strptime-bug/m-p/26582#M5150</link>
      <description>&lt;P&gt;Seems to have done the trick - thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 17:34:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Strptime-bug/m-p/26582#M5150</guid>
      <dc:creator>ARothman</dc:creator>
      <dc:date>2012-11-08T17:34:40Z</dc:date>
    </item>
  </channel>
</rss>

