Getting Data In

How do i query splunk for latest and earliest time based on epoch time rather than human readable time?

tikoonikhil
Explorer

I have a field called as "impact_time" which has human readable dates in it. Now i want to query splunk for a range of impact_time. The only problem is that the earliest and latest time that i have is in epoch format. How do i make splunk query based on the epoch time range that i am passing?

0 Karma

inventsekar
Super Champion

you can use epoch times for earliest and latest

index=bar sourcetype=foo earliest=1350538170 latest=1350538870 | more search commands
>>> Happy Splunking !
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...