Splunk Dev

Convert "20180328212007.496740+180" to human readable format?

test_qweqwe
Builder

Hi.
How to convert "20180328212007.496740+180" to human readable format?
And if possible without ignores the time zone offset (+180)?

Tags (1)
0 Karma

deepashri_123
Motivator

hey@test_qweqwe,

This does not look like an epoch.
Can you try this:
eval time=strftime(strptime("yourtime","%Y%m%d%H%M%S.%6Q+%Ez"),"%Y/%m/%d %H:%M:%S")

Let me know if this helps!!

test_qweqwe
Builder

I have No results found.

InstallDate="20170901111017.000000+180"
LastBootUpTime="20180314062957.183621+120"

| eval LastBootUpTime=strftime(strptime("LastBootUpTime","%Y%m%d%H%M%S.%6Q+%Ez"),"%Y/%m/%d %H:%M:%S")

0 Karma

ckeller2791
Explorer

This worked for me.

|eval LastBoot=strftime(strptime(LastBootUpTime,"%Y%m%d%H%M%S.%N%Z"),"%Y/%m/%d %H:%M:%S")

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...