<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Date displaying as a string in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Date-displaying-as-a-string/m-p/329679#M98141</link>
    <description>&lt;P&gt;This worked for me.  This is the part that I was missing "(now()-7*24*3600"  Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 17:09:33 GMT</pubDate>
    <dc:creator>cc3658</dc:creator>
    <dc:date>2020-09-29T17:09:33Z</dc:date>
    <item>
      <title>Date displaying as a string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Date-displaying-as-a-string/m-p/329677#M98139</link>
      <description>&lt;P&gt;I have a string field (publication_date) that is displaying a date in the following format YYYY/mm/dd.   Ultimately I would like to display in a dashboard any logs displaying a publication_date within the last 7 days.  &lt;/P&gt;

&lt;P&gt;I suspect I am having trouble because it is a sting field and not numeric but have been unsuccessful in finding the correct syntax.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:09:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Date-displaying-as-a-string/m-p/329677#M98139</guid>
      <dc:creator>cc3658</dc:creator>
      <dc:date>2020-09-29T17:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: Date displaying as a string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Date-displaying-as-a-string/m-p/329678#M98140</link>
      <description>&lt;P&gt;In general, you want the &lt;CODE&gt;strptime()&lt;/CODE&gt; function to change the display format into epoch time format, and &lt;CODE&gt;strftime()&lt;/CODE&gt; to go the other way.&lt;/P&gt;

&lt;P&gt;However, in this case, because the ISO format you showed will sort dates into the same order, you can just change  current date - 7 days into the same format and compare directly.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  | eval testDate = strftime(now()-7*24*3600,"%Y/%m/%d")
  | where publication_date &amp;gt;= testDate
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Change &lt;CODE&gt;&amp;gt;=&lt;/CODE&gt; to &lt;CODE&gt;&amp;gt;&lt;/CODE&gt; if you want to exclude the date one week ago (ie exclude last Friday if today is Friday).&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 21:21:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Date-displaying-as-a-string/m-p/329678#M98140</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-12-06T21:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Date displaying as a string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Date-displaying-as-a-string/m-p/329679#M98141</link>
      <description>&lt;P&gt;This worked for me.  This is the part that I was missing "(now()-7*24*3600"  Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:09:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Date-displaying-as-a-string/m-p/329679#M98141</guid>
      <dc:creator>cc3658</dc:creator>
      <dc:date>2020-09-29T17:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: Date displaying as a string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Date-displaying-as-a-string/m-p/329680#M98142</link>
      <description>&lt;P&gt;@cc3658 - in real code, I'd multiply that out, but for the forum I wanted it to be obvious what the number meant.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 22:36:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Date-displaying-as-a-string/m-p/329680#M98142</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-12-06T22:36:07Z</dc:date>
    </item>
  </channel>
</rss>

