I tried this but seems this is not working.
I want to convert BST to America /NY time please.
| eval BST=strftime(TransactTime/1000000000, "%d/%m/%y %H:%M:%S %Z" )
| eval TimeZone=BST+" -EST"
| eval ET=strftime(strptime(TimeZone,"%d/%m/%y %H:%M:%S %Z"),"%d/%m/%y %H:%M:%S %Z")
| table BST, ET
| makeresults
| eval h_time=strftime(_time,"%FT%T")
| eval est_time=strptime(h_time."-0500","%FT%T%z")
| convert ctime(est_time)
I tried this it didn't work.
First of all it complained about the format of strftime so I changed it to
| eval BST=strftime(TransactTime/1000000000, "%d/%m/%y %H:%M:%S %Z" )
| eval NY=strptime(BST."-0500","%d/%m/%y %H:%M:%S %Z")
| convert ctime(BST)
| table host, BST, NY, TransactTime
https://docs.splunk.com/Documentation/Splunk/8.0.5/SearchReference/Commontimeformatvariables
see reference.
%Z and %z mean different.