Getting Data In

returns both time and date together

smolcj
Builder

Hi,
Using _time we will get the time of the event. so by using earliest(_time), time is produced as the result. is there any function to return both date and time. i.e. time stamp together.

thank you for your time

Tags (1)
0 Karma
1 Solution

Ayn
Legend

Are you asking how to convert the _time value that you get in epoch format to something more humanly readable? In that case, use convert ctime(earliest(_time)) for that.

View solution in original post

0 Karma

Ayn
Legend

Are you asking how to convert the _time value that you get in epoch format to something more humanly readable? In that case, use convert ctime(earliest(_time)) for that.

0 Karma

smolcj
Builder

thanks AYN it worked well with ctime

..| convert ctime(_time) as time|stats earliest(time)

0 Karma
Get Updates on the Splunk Community!

Alpha Launch: AI-Assisted Auto-Schematization for CIM

Streamlining Data Onboarding: Announcing the Alpha Release of AI-Assisted Auto-Schematization For many Splunk ...

Enterprise Security(ES) Essentials or Premier? Let's discuss Splunk ES Editions on ...

  Hi everyone, Last year at .conf25, we shared something exciting: Splunk Enterprise Security is evolving ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 5

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...