I have a field returned with some search data that contains a date and time in UTC. I would like to be able to add 10 hours to the time.
a) Field contents(dateTime UTC): 2023-05-08T00:24:37.6079338Z
b) New field (Local dateTime): 2023-05-08 10:24:37.607
Is there a way to do the conversion from a) to b) in the search syntax?
Hi @balcv,
You can use below;
| eval newtime=strftime(strptime(datefield,"%Y-%m-%dT%H:%M:%S.%7QZ")+36000,"%Y-%m-%dT%H:%M:%S.%3QZ")
Perfect thanks @scelikok