Splunk Search

Difference between two dates

ncbshiva
Communicator

I have a log that has
Start date=2003-11-20 00:00:00,End date=2079-06-06 00:00:00.
I want to calculate the difference between the Enddate and Startdate, and display the difference in both days and in years.

Please help me

Tags (1)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

For days you can do this:

...  | eval days = round((strptime(Enddate, "%F %T") - strptime(Startdate, "%F %T")) / 86400)

For years it depends on what you want to see.

Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...