Hi Team,
I am finding a way to convert UTC to EPOCH and vice versa for my search query
Sample is here -> date: 2021-09-04 08:25:56 UTC
strptime() and strftime() are functions you use to convert between string representation and unix timestamp. But remember that instead of creating a field with string representation of a date you can do a fieldformat, so that internally splunk manipulates the timestamp as integer (it's much easier to do date arithmetics this eay) and only presents the results rendered to given string format.
strptime (parse) and strftime (format) https://docs.splunk.com/Documentation/Splunk/8.2.2/SearchReference/DateandTimeFunctions
I am trying this way,
| makeresults
| eval time ="2021-09-04 08:25:56 UTC"
| eval time_ephoc= strptime(time , "%Y-%m-%d %H:%M:%S")| eval timebackUTC=strftime(time_ephoc,"%Y-%m-%d %H:%M:%S UTC")