All Apps and Add-ons

Why is strptime not working with Calendar - Custom Visualization?

kiran331
Builder

Hi

I want to show the Logon time and logoff time and duration in calendar customization in human readable format but its not working when I convert epoch time in to readable format.

search i'm using:

index=cisco_wsa user=abcdk| eval time=_time | timechart span=1d min(time) as "LogonTime", max(time) as "LogoffTime"|eval Duration=(LogoffTime - LogonTime)/3600 |convert  timeformat="%m/%d/%y %H:%M:%S" ctime(*)
0 Karma

jconger
Splunk Employee
Splunk Employee

The calendar custom visualization is expecting numerical data for the values which is similar to a line chart. Basically, if it works on a line chart, it should work on the calendar as well.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you tried using fieldformat?

index=cisco_wsa user=acdkn002 | eval time=_time | timechart span=1d min(time) as "LogonTime", max(time) as "LogoffTime"|eval Duration=(LogoffTime - LogonTime)/3600 |fieldformat LogonTime=strftime(LogonTime,"%m/%d/%y %H:%M:%S") |fieldformat LogoffTime =strftime(LogoffTime ,"%m/%d/%y %H:%M:%S")
---
If this reply helps you, Karma would be appreciated.
0 Karma

kiran331
Builder

I tried, its not working.

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...