Splunk Search

Calculating difference between two strftime fields

jason_hotchkiss
Communicator

Hello Splunkers:

I'm looking to determine how many days file is out of date.

I have two strftime fields and values:

x = 1612285190.000
y = 1612303190.000000

I need to calculate the number of days between x and y, something like x - y = z.  

I tried: 
| eval z=x-y 

y calculates to -18000.00

I tried converting this using:
| eval x=strftime(z, "d%") and I get 31.  Which seems to be the 31st day of the month.  

Thanks in advance.

Labels (2)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

Hi @jason_hotchkiss,

You are very close, you can achieve this in two ways;

This will give you days;
| eval z=round((x-y)/86400,0)
This will give you timeformatted;
| eval z=tostring(x-y,"duration")

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @jason_hotchkiss,

You are very close, you can achieve this in two ways;

This will give you days;
| eval z=round((x-y)/86400,0)
This will give you timeformatted;
| eval z=tostring(x-y,"duration")

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

jason_hotchkiss
Communicator

Awesome, thank you!

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...

Major Splunk Upgrade – Prepare your Environment for Splunk 10 Now!

Attention App Developers: Test Your Apps with the Splunk 10.0 Beta and Ensure Compatibility Before the ...

Stay Connected: Your Guide to June Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...