Splunk Search

How to convert feb 1 01:03:20 2018 to epoch time?

priyanka0309
New Member

I am pulling data from DB connect to splunk. The DB has time value
feb 1 01:03:20 2018. I should convert this field to epoch time.

I am using the command eval reporteddate = strptime(LAST_UPDATE, "%m %d %Hh:%Mm:%Ss %Y") . Please let me know how to proceed with this

Tags (2)
0 Karma

somesoni2
Revered Legend

Try eval reporteddate = strptime(LAST_UPDATE, "%b %d %H:%M:%S %Y"). See this splunk documentation for time format variables that can be used.
https://docs.splunk.com/Documentation/Splunk/7.0.2/SearchReference/Commontimeformatvariables

abhishekroy168
Path Finder

I downvoted this post because still getting empty value for time

0 Karma

niketn
Legend

I am up voting the post because it works as expected for the provided sample date feb 1 01:03:20 2018
Following is the run anywhere search to test the same:

| makeresults
| eval LAST_UPDATE="feb 1 01:03:20 2018"
| eval reporteddate = strptime(LAST_UPDATE, "%b %d %H:%M:%S %Y")

@abhishekroy168, For us to assist you better, can you please provide sample Date format of what you have. If it differs from this question you can post your own question.

Downvoting should only be reserved for suggestions/solutions that could be potentially harmful for a Splunk environment or goes completely against known best practices. Simply commenting with constructive feedback on the post you are concerned with will be more beneficial for the community to learn from.

Some of the most active members in Answers have helped set the standard of how voting etiquette should work in the Splunk community which distinguishes our culture apart from other Q&A forums. Upvote early and often to give credit where it’s due for high quality posts, comment where you think feedback needs to be given, and only downvote if something potentially dangerous is suggested or people are just being inappropriate.

If you’re interested in seeing how this voting etiquette was developed, check out this Splunk Answers post: https://answers.splunk.com/answers/244111/proper-etiquette-and-timing-for-voting-here-on-ans.htmlon-...

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...