Splunk Search

How to calculate dates in splunk?

ositaumeozulu
Explorer

again i wanted to list difference in dates between two periods and i have this code

| eval LPD = strptime(LastPickupDate, "%m-%d-%Y %H:%M:%S")
| eval IInT = strptime(IIT, "%m-%d-%Y %H:%M:%S")
| eval diff = (IInT-LPD)/86400

| stats list(diff) by FacilityName

still getting blanks 

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ositaumeozulu,

let me understand: in each event you have LastPickupDate and IIT in those formats and FacilityName, is this correct?

Check if you have all the three fields in each event and check the date formats.

Ciao.

Giuseppe

 

0 Karma

ositaumeozulu
Explorer

Hi @gcusello 

Many thanks, has gotten the hang of it, for the format i was using - instead of / as in my format, thanks for all your helps, the whole codes are working now

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ositaumeozulu,

good for you, see next time!

Please accept one answer for the other people of Community

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

ositaumeozulu
Explorer

Hi @gcusello 

please let me upload the screenshot of the formats you asked for

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...