<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to do operations with dates fields? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-do-operations-with-dates-fields/m-p/179472#M51666</link>
    <description>&lt;P&gt;Hi bruno_eduardo,&lt;/P&gt;

&lt;P&gt;I would compare epoch times not human readable time stamps.&lt;/P&gt;

&lt;P&gt;So something like this will do it:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | eval now_time=now() 
| convert mktime("Resolution Period") AS Resolution_Period
| where Resolution_Period &amp;gt; now_time
| table Resolution_Period
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;regarding the future timestamp you can try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | eval future_time=relative_time(now(), "+15d") | ...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;this will return an epoch timestamp as well.&lt;/P&gt;

&lt;P&gt;hope this helps ....&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Tue, 04 Nov 2014 12:58:10 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2014-11-04T12:58:10Z</dc:date>
    <item>
      <title>How to do operations with dates fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-do-operations-with-dates-fields/m-p/179471#M51665</link>
      <description>&lt;P&gt;Got a date field that I would like to return only events that were within a specific range, from today to 15 days in the future.&lt;BR /&gt;
To get today:&lt;BR /&gt;
|eval timenow=now() |eval nowstring=strftime(now(),"%d/%m/%Y %H:%M:%S")&lt;BR /&gt;
|table nowstring&lt;BR /&gt;
04/11/2014 10:35:59&lt;/P&gt;

&lt;P&gt;My date field is already like this:&lt;BR /&gt;
|table "Resolution Period"&lt;BR /&gt;
27/01/2014 23:59:59&lt;/P&gt;

&lt;P&gt;But when I try a simple search like this:&lt;BR /&gt;
|where "Resolution Period" &amp;gt; nowstring |table "Resolution Period"&lt;BR /&gt;
I still got all events, unfiltered. Do I need to change something on the "Resolution Period"??&lt;/P&gt;

&lt;P&gt;And How to return only events that were within a specific range, from today to 15 days in the future.???&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2014 12:21:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-do-operations-with-dates-fields/m-p/179471#M51665</guid>
      <dc:creator>bruno_eduardo</dc:creator>
      <dc:date>2014-11-04T12:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to do operations with dates fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-do-operations-with-dates-fields/m-p/179472#M51666</link>
      <description>&lt;P&gt;Hi bruno_eduardo,&lt;/P&gt;

&lt;P&gt;I would compare epoch times not human readable time stamps.&lt;/P&gt;

&lt;P&gt;So something like this will do it:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | eval now_time=now() 
| convert mktime("Resolution Period") AS Resolution_Period
| where Resolution_Period &amp;gt; now_time
| table Resolution_Period
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;regarding the future timestamp you can try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | eval future_time=relative_time(now(), "+15d") | ...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;this will return an epoch timestamp as well.&lt;/P&gt;

&lt;P&gt;hope this helps ....&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2014 12:58:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-do-operations-with-dates-fields/m-p/179472#M51666</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-11-04T12:58:10Z</dc:date>
    </item>
  </channel>
</rss>

