Splunk Search

How to calculate the number of days from a create date to the current date?

itsmevic70
Explorer

 

 

index=servicenow assignment_group_name="security" status=*
| stats count by number,status,group_name,created_on

 

 

The above query will produce the following:

Splunk Days Inbetwen Calculation.JPGI need to calculate the number days from the "created on" date shown above in the example to the current date.  

Any help with this is greatly appreciated.

Labels (2)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

Add

| eval days=round((now() - strptime(created_on, "%d-%b-%y %H:%M:%S")) / 86400, 0)

to calculate days - this rounds to 0 decimal places. Change as required or use floor() to round down if wanted.

View solution in original post

Tags (1)

itsmevic70
Explorer

Thank you.

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Add

| eval days=round((now() - strptime(created_on, "%d-%b-%y %H:%M:%S")) / 86400, 0)

to calculate days - this rounds to 0 decimal places. Change as required or use floor() to round down if wanted.

Tags (1)
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...