Splunk Search

How to calculate dates in splunk?

ositaumeozulu
Explorer

again i wanted to list difference in dates between two periods and i have this code

| eval LPD = strptime(LastPickupDate, "%m-%d-%Y %H:%M:%S")
| eval IInT = strptime(IIT, "%m-%d-%Y %H:%M:%S")
| eval diff = (IInT-LPD)/86400

| stats list(diff) by FacilityName

still getting blanks 

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ositaumeozulu,

let me understand: in each event you have LastPickupDate and IIT in those formats and FacilityName, is this correct?

Check if you have all the three fields in each event and check the date formats.

Ciao.

Giuseppe

 

0 Karma

ositaumeozulu
Explorer

Hi @gcusello 

Many thanks, has gotten the hang of it, for the format i was using - instead of / as in my format, thanks for all your helps, the whole codes are working now

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ositaumeozulu,

good for you, see next time!

Please accept one answer for the other people of Community

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

ositaumeozulu
Explorer

Hi @gcusello 

please let me upload the screenshot of the formats you asked for

0 Karma
Get Updates on the Splunk Community!

Manual Instrumentation with Splunk Observability Cloud: The What and Why

If you've ever worked with distributed systems, you’ve likely felt the pain of a frontend throwing errors, ...

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and ...

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and Splunk ES Protecting a ...

It's Customer Success Time at .conf25

Hello Splunkers,   Ready for .conf25? The customer success and experience team is and can’t wait to see you ...