Splunk Search

Filter by time where date is in seperate field

user93
Communicator

I need some help to filter by time, but the time field is not the internal Splunk time field. Instead, it is a date field from a lookup spreadsheet that corresponds to the objects file creation.

I want to be able to filter on objects that are created only in the previous month.

The format of the lookup date field is like this:

Created=8/26/2019 17:01

Tags (2)
0 Karma

eduardKiyko
Explorer

You can create _time field right in search query, like this:


| eval _time=strptime(Created,"%Y-%m-%d %H:%M:%S")

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...