Getting Data In
Highlighted

How do i query splunk for latest and earliest time based on epoch time rather than human readable time?

Explorer

I have a field called as "impacttime" which has human readable dates in it. Now i want to query splunk for a range of impacttime. The only problem is that the earliest and latest time that i have is in epoch format. How do i make splunk query based on the epoch time range that i am passing?

0 Karma
Highlighted

Re: How do i query splunk for latest and earliest time based on epoch time rather than human readable time?

Champion

you can use epoch times for earliest and latest

index=bar sourcetype=foo earliest=1350538170 latest=1350538870 | more search commands