All Apps and Add-ons

Get element from index with specific date format

wawanopoulos
New Member

Hi,

My index contain a column "deliveryDate" with the following format : 2015-10-08
I would build a search to get all data from my index where deliveryDate > dateNow.

I cannot user earliest and latest keyword i think because it is not the same format of date.

Could you help me please ?

0 Karma

woodcock
Esteemed Legend

Like this:

... | eval deliveryDateEpoch=strptime(deliveryDate, "%Y-%m-%d") | where  deliveryDateEpoch>now()
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...