Reporting

Remove T ffrom the timestamp and find the different two different time column

ravir_jbp
Explorer

 

Able to get event output in table format. But looking for eval condition:

1. Remove T from the timestamp and convert the below UTC/GMT to EST and need this in YYYY-MM-DD HH:MM:SS

2. And need the time different between c_timestamp and c_mod and add the time difference in Timetaknen column.

 

Capture.JPG

Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Change your global time zone to be your local time zone e.g. EST.

To calculate differences in times you need to parse the strings to epoch format

| eval epoch_timestamp=strptime(c_timestamp,"%FT%T.%6N%z")
| eval local_timestamp=strftime(epoch_timestamp,"%F %T.%6N %Z")
| eval epoch_mod=strptime(c_mod,"%FT%T.%6N%z")
| eval local_mod=strftime(epoch_mod,"%F %T.%6N %Z")
| eval diff=epoch_mod-epoch_timestamp
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...