Splunk Search

Can you help me with my string to date query?

serviceinfrastr
Explorer

Hi Community ,

I have a question about a conversion beetwen string to date.

I have some extract in CSV from my google platform like this :

> host=DSCRIPT02 sourcetype=csv:google | eval lastSync-mod=substr(lastSync,1,10)  | search "lastSync-mod"!=Never AND  "lastSync-mod"!=LastSync | table  resourceId email lastSync-mod | sort lastSync-mod | head 20

I have the last 20 mobiles, but i want the the list of mobiles that was not sync until 30days. The problem is the field last-Sync-Mod is not recognized as a date format

alt text

Can you help me 🙂 ?

Many thanks

Tags (2)
0 Karma

renjith_nair
Legend

@serviceinfrastructure,

Try

"Your search "|eval last_sync_time=strptime(lastSync-mod,"%Y-%m-%d")|eval diff=(now()-last_sync_time)/86400|where diff>30
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...