Reporting

Remove T ffrom the timestamp and find the different two different time column

ravir_jbp
Explorer

 

Able to get event output in table format. But looking for eval condition:

1. Remove T from the timestamp and convert the below UTC/GMT to EST and need this in YYYY-MM-DD HH:MM:SS

2. And need the time different between c_timestamp and c_mod and add the time difference in Timetaknen column.

 

Capture.JPG

Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Change your global time zone to be your local time zone e.g. EST.

To calculate differences in times you need to parse the strings to epoch format

| eval epoch_timestamp=strptime(c_timestamp,"%FT%T.%6N%z")
| eval local_timestamp=strftime(epoch_timestamp,"%F %T.%6N %Z")
| eval epoch_mod=strptime(c_mod,"%FT%T.%6N%z")
| eval local_mod=strftime(epoch_mod,"%F %T.%6N %Z")
| eval diff=epoch_mod-epoch_timestamp
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...