Splunk Search

Days Between Question

jhayIV
Engager

I am trying to determine the days between a static date and current date

in this query I added a the 2008r2 column with a static date - table Division Name OS _time | eval 2008r2="1/14/2020"|

I was unable to use a previous eval statement on this, I assume I dont have that column formatted properly
eval Days=round((2008r2(now(),"@d")-relative_time(2008r2,"@d"))/86400,0)

0 Karma

somesoni2
Revered Legend

Use like this

...table Division Name OS _time | eval 2008r2="1/14/2020"| eval Days=round((relative_time(now(),"@d")-relative_time(strptime('2008r2',"%m/%d/%Y"),"@d"))/86400,0) 

Basically, you need to convert your string date to epoch format so that you can do mathematical operation with current time now() which is in epoch. (the relative_time function also only accepts epoch value).

0 Karma

woodcock
Esteemed Legend

We need to see sample event data and your full search.

0 Karma
Get Updates on the Splunk Community!

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...