Splunk Enterprise

help for doing difference between 2 dates

jip31
Motivator

hi

I need to calculate the duration difference between 2 dates and having the result in seconds

The field "Debut chargement Profile" correspond to the beginning and the field "Fin chargement Profile" correspond to the end

the timestamp format is the following : 

13/09/2021 11:00:06,000

how to do this please?

Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| eval diff=strptime('Fin chargement Profile',"%d/%m/%Y %H:%M:%S,%Q")-strptime('Debut chargement Profile',"%d/%m/%Y %H:%M:%S,%Q")

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval diff=strptime('Fin chargement Profile',"%d/%m/%Y %H:%M:%S,%Q")-strptime('Debut chargement Profile',"%d/%m/%Y %H:%M:%S,%Q")
0 Karma

jip31
Motivator

many thanks

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...