Splunk Search

Change time field to show 'x' minutes ago?

zoebanning
Path Finder

Hello Splunk Community, 

I have a stats table I have created and I want to change the time field ("%Y-%m-%d %H:%M:%S") to present 'x' minutes ago. 

Can anyone help with this? 

Many Thanks, 

Zoe

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

The part you need is the now() - _time line below

| makeresults count=10
| eval _time=_time-(random() % (55 * 60))
| sort - _time
| eval mins=round(((now() - _time) / 60))." minutes ago"

this will round down the number of minutes. I'm assuming your time field is from the _time field, which is the epoch time in seconds, so just using the now() function to calculate the difference.

 

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

Just add/substract needed number of seconds to adjust your timestamp.

For example, to "offset" all results by 10 minutes into the past do:

| eval _time=_time-600

 The question is - do you have the timestamp as timestamp (integer) or did you already render it to a string. If it's a string, you have to of course convert it to a timestamp with strptime or - even better - find earlier place in your spl pipeline when the timestamp was still nummerical and get your "source" timestamp from there.

0 Karma

bowesmana
SplunkTrust
SplunkTrust

The part you need is the now() - _time line below

| makeresults count=10
| eval _time=_time-(random() % (55 * 60))
| sort - _time
| eval mins=round(((now() - _time) / 60))." minutes ago"

this will round down the number of minutes. I'm assuming your time field is from the _time field, which is the epoch time in seconds, so just using the now() function to calculate the difference.

 

zoebanning
Path Finder

Thank you! Worked out perfectly 🙂

0 Karma
Get Updates on the Splunk Community!

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...