Splunk Search

Days Between Question

jhayIV
Engager

I am trying to determine the days between a static date and current date

in this query I added a the 2008r2 column with a static date - table Division Name OS _time | eval 2008r2="1/14/2020"|

I was unable to use a previous eval statement on this, I assume I dont have that column formatted properly
eval Days=round((2008r2(now(),"@d")-relative_time(2008r2,"@d"))/86400,0)

0 Karma

somesoni2
Revered Legend

Use like this

...table Division Name OS _time | eval 2008r2="1/14/2020"| eval Days=round((relative_time(now(),"@d")-relative_time(strptime('2008r2',"%m/%d/%Y"),"@d"))/86400,0) 

Basically, you need to convert your string date to epoch format so that you can do mathematical operation with current time now() which is in epoch. (the relative_time function also only accepts epoch value).

0 Karma

woodcock
Esteemed Legend

We need to see sample event data and your full search.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...