I'm stuck trying to figure out the conversion on this time format field from Active Directory data. Hoping someone can assist? I am not sure how do the syntax to deal with the comma and day of the week components... Haven't seen that in Splunk events to date.
I'm trying to convert this to epoch time so I can do math and see how old it is from now()
05:20.55 PM, Mon 12/17/2018
strptime(lastLogonTimestamp, "%H:%M:%S %p %m/%d/%Y") - not working.
Still not getting anything from either of these tips... Tried %A and %a neither seem to matter.
lastLogonTimestamp value is 12:58.51 PM, Tue 12/11/2018
| head 10
| eval logintime = strptime(lastLogonTimestamp, "%H:%M:%S %p, %a %m/%d/%Y")
| eval timenow = now()
| table lastLogonTimestamp logintime timenow