Splunk Search

How to convert a lookup date field to epoch

theouhuios
Motivator

Hello

I have a lookup table which has a Datetime field like 1/20/2013 or 4/29/2013. Now I need to convert it to epoch time to compare it to the normal time when the search ran. We can take the H:M:S as 00:00:00.

Any idea on what can be done?

Thanks

Tags (1)
0 Karma

rturk
Builder

Hi Theouhuios,

What you will need to do is specify in the lookup definition (in transforms.conf) that one of the fields is in fact a time value. There shouldn't be any need to convert it to epoch seconds.

Example:

[eventLookup]
filename = events.csv
time_field = Datetime
time_format = %m/%d/%Y

Without the hours, minutes, and seconds being defined it should default to 00:00:00.

Hope this helps 🙂

Ref: http://docs.splunk.com/Documentation/Splunk/5.0.4/Knowledge/Addfieldsfromexternaldatasources#Set_up_...

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...