Splunk Search

Can you help me with my string to date query?

serviceinfrastr
Explorer

Hi Community ,

I have a question about a conversion beetwen string to date.

I have some extract in CSV from my google platform like this :

> host=DSCRIPT02 sourcetype=csv:google | eval lastSync-mod=substr(lastSync,1,10)  | search "lastSync-mod"!=Never AND  "lastSync-mod"!=LastSync | table  resourceId email lastSync-mod | sort lastSync-mod | head 20

I have the last 20 mobiles, but i want the the list of mobiles that was not sync until 30days. The problem is the field last-Sync-Mod is not recognized as a date format

alt text

Can you help me 🙂 ?

Many thanks

Tags (2)
0 Karma

renjith_nair
Legend

@serviceinfrastructure,

Try

"Your search "|eval last_sync_time=strptime(lastSync-mod,"%Y-%m-%d")|eval diff=(now()-last_sync_time)/86400|where diff>30
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...