Getting Data In

returns both time and date together

smolcj
Builder

Hi,
Using _time we will get the time of the event. so by using earliest(_time), time is produced as the result. is there any function to return both date and time. i.e. time stamp together.

thank you for your time

Tags (1)
0 Karma
1 Solution

Ayn
Legend

Are you asking how to convert the _time value that you get in epoch format to something more humanly readable? In that case, use convert ctime(earliest(_time)) for that.

View solution in original post

0 Karma

Ayn
Legend

Are you asking how to convert the _time value that you get in epoch format to something more humanly readable? In that case, use convert ctime(earliest(_time)) for that.

0 Karma

smolcj
Builder

thanks AYN it worked well with ctime

..| convert ctime(_time) as time|stats earliest(time)

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...