Getting Data In

How do i query splunk for latest and earliest time based on epoch time rather than human readable time?

tikoonikhil
Explorer

I have a field called as "impact_time" which has human readable dates in it. Now i want to query splunk for a range of impact_time. The only problem is that the earliest and latest time that i have is in epoch format. How do i make splunk query based on the epoch time range that i am passing?

0 Karma

inventsekar
SplunkTrust
SplunkTrust

you can use epoch times for earliest and latest

index=bar sourcetype=foo earliest=1350538170 latest=1350538870 | more search commands
thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...