Getting Data In

Concat time field to include start to end of hour

benj851
Explorer

Hello; 

I've tried a few ways, but have been unsuccessful in creating a _time field to include the datetime, and the end hour. Ex. 06/18/2021 08:00 - 08:59. I'd appreciate any assistance in getting there. 

When concating, the time field converts to unix. Then I can't convert it back to CTIME. 

Here's an example of the data pulled: 

index=foo host=hostfoo sourcetype=sourcefoo
| bin span=1h _time
| table _time

_time

2021-06-18 08:00

 

Desired: 

_time

2021-06-18 08:00 - 08:59
Labels (2)
0 Karma
1 Solution

aasabatini
Builder

Hi @benj851 

try like this

 

<your search>
| eval date=strftime(_time, "%Y/%m/%d %H:%M")
| eval hour=strftime(_time, "%H")
| eval timestamp=date." "."-"." ".hour.":"."59"

 

View solution in original post

0 Karma

aasabatini
Builder

Hi @benj851 

try like this

 

<your search>
| eval date=strftime(_time, "%Y/%m/%d %H:%M")
| eval hour=strftime(_time, "%H")
| eval timestamp=date." "."-"." ".hour.":"."59"

 

View solution in original post

0 Karma

benj851
Explorer

Perfect thank you.

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.