Getting Data In

Convert Epoch timestamp

satishsdange
Builder

I am trying to convert epoch timestamp of stopTime into %m/%d/%Y %H:%M:%S , but I am getting 12/31/9999 23:59:59

"traceId":xxxxx,"startTime":1395740488120,"stopTime":1395740497550

This is what I am using -

rex "^(?:[^:\n]*:){3}(?P<endtime>\d+)" | eval StopTime=strftime(endtime, "%m/%d/%Y %H:%M:%S")

Could someone please let me know what could be the problem?

TIA

0 Karma
1 Solution

vganjare
Builder

Hi,

Are you using the time in millisecond format? Please see following time comparison:
1427110824 - Epoch time for today
1395740497550

If you divide endtime by 1000, it should work fine.

Thanks!

View solution in original post

0 Karma

vganjare
Builder

Hi,

Are you using the time in millisecond format? Please see following time comparison:
1427110824 - Epoch time for today
1395740497550

If you divide endtime by 1000, it should work fine.

Thanks!

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...