- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

davidcraven02
Communicator
04-10-2018
07:44 AM
How could I convert this GMT time to EDT?
index="wineventlog" host=opdc* Account_Name=*test_user EventCode=4624
| makemv Account_Name
| mvexpand Account_Name
| eval day=strftime(_time, "%d-%m-%y")
| join type=left src_ip
[ search index=ad source=addnsscan earliest=-12h@h latest=now
| rename data as src_ip, name as hostname
| fields src_ip, hostname]
| stats earliest(_time) AS earliest by Account_Name, src_ip, hostname, day
| eval earliest=strftime(earliest,"%d/%m/%Y %H.%M.%S %Z")
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

somesoni2
Revered Legend
04-10-2018
08:05 AM
Give this a try
Updated
index="wineventlog" host=opdc* Account_Name=*test_user EventCode=4624
| makemv Account_Name
| mvexpand Account_Name
| eval day=strftime(_time, "%d-%m-%y")
| join type=left src_ip
[ search index=ad source=addnsscan earliest=-12h@h latest=now
| rename data as src_ip, name as hostname
| fields src_ip, hostname]
| stats earliest(_time) AS earliest by Account_Name, src_ip, hostname, day
| eval offset=strptime("00:00Z","%H:%M%Z")-strptime("00:00EDT","%H:%M%Z")
| eval earliest=strftime(earliest+offset,"%d/%m/%Y %H.%M.%S %Z")
| fields - offset
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

somesoni2
Revered Legend
04-10-2018
08:05 AM
Give this a try
Updated
index="wineventlog" host=opdc* Account_Name=*test_user EventCode=4624
| makemv Account_Name
| mvexpand Account_Name
| eval day=strftime(_time, "%d-%m-%y")
| join type=left src_ip
[ search index=ad source=addnsscan earliest=-12h@h latest=now
| rename data as src_ip, name as hostname
| fields src_ip, hostname]
| stats earliest(_time) AS earliest by Account_Name, src_ip, hostname, day
| eval offset=strptime("00:00Z","%H:%M%Z")-strptime("00:00EDT","%H:%M%Z")
| eval earliest=strftime(earliest+offset,"%d/%m/%Y %H.%M.%S %Z")
| fields - offset
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

davidcraven02
Communicator
04-10-2018
09:28 AM
Thank you for this but the earliest field is blank.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

somesoni2
Revered Legend
04-10-2018
10:44 AM
Try the updated answer. Fixed a typo in first strptime in eval for offset.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

davidcraven02
Communicator
04-10-2018
12:51 PM
Perfect thank you!!
