Splunk Search

Days Between Question

jhayIV
Engager

I am trying to determine the days between a static date and current date

in this query I added a the 2008r2 column with a static date - table Division Name OS _time | eval 2008r2="1/14/2020"|

I was unable to use a previous eval statement on this, I assume I dont have that column formatted properly
eval Days=round((2008r2(now(),"@d")-relative_time(2008r2,"@d"))/86400,0)

0 Karma

somesoni2
Revered Legend

Use like this

...table Division Name OS _time | eval 2008r2="1/14/2020"| eval Days=round((relative_time(now(),"@d")-relative_time(strptime('2008r2',"%m/%d/%Y"),"@d"))/86400,0) 

Basically, you need to convert your string date to epoch format so that you can do mathematical operation with current time now() which is in epoch. (the relative_time function also only accepts epoch value).

0 Karma

woodcock
Esteemed Legend

We need to see sample event data and your full search.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...