Splunk Search

How to calculate dates in splunk?

ositaumeozulu
Explorer

again i wanted to list difference in dates between two periods and i have this code

| eval LPD = strptime(LastPickupDate, "%m-%d-%Y %H:%M:%S")
| eval IInT = strptime(IIT, "%m-%d-%Y %H:%M:%S")
| eval diff = (IInT-LPD)/86400

| stats list(diff) by FacilityName

still getting blanks 

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ositaumeozulu,

let me understand: in each event you have LastPickupDate and IIT in those formats and FacilityName, is this correct?

Check if you have all the three fields in each event and check the date formats.

Ciao.

Giuseppe

 

0 Karma

ositaumeozulu
Explorer

Hi @gcusello 

Many thanks, has gotten the hang of it, for the format i was using - instead of / as in my format, thanks for all your helps, the whole codes are working now

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ositaumeozulu,

good for you, see next time!

Please accept one answer for the other people of Community

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

ositaumeozulu
Explorer

Hi @gcusello 

please let me upload the screenshot of the formats you asked for

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...