Getting Data In
Highlighted

returns both time and date together

Builder

Hi,
Using time we will get the time of the event. so by using earliest(time), time is produced as the result. is there any function to return both date and time. i.e. time stamp together.

thank you for your time

Tags (1)
0 Karma
Highlighted

Re: returns both time and date together

Legend

Are you asking how to convert the _time value that you get in epoch format to something more humanly readable? In that case, use convert ctime(earliest(_time)) for that.

View solution in original post

0 Karma
Highlighted

Re: returns both time and date together

Builder

thanks AYN it worked well with ctime

..| convert ctime(_time) as time|stats earliest(time)

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.