Splunk Search

How to edit my eval syntax to convert a date from Active Directory to epoch time?

kiran331
Builder

Hi

How to convert the date format from the active directory to epoch time?

date format:

2016-10-23T05:00:00Z

I tried:

....|eval endDate= strptime(accountExpires,"%Y-%m-%dT%H:%M:%SZ")

but it's not showing anything.

0 Karma
1 Solution

sundareshr
Legend

Try this

| makeresults | eval accountExpires="2016-10-23T05:00:00Z"|eval endDate= strptime(accountExpires,"%Y-%m-%dT%H:%M:%S")  | eval x=strftime(endDate, "%Y-%m-%dT%H:%M:%S") | table accountExpires endDate x

View solution in original post

0 Karma

sundareshr
Legend

Try this

| makeresults | eval accountExpires="2016-10-23T05:00:00Z"|eval endDate= strptime(accountExpires,"%Y-%m-%dT%H:%M:%S")  | eval x=strftime(endDate, "%Y-%m-%dT%H:%M:%S") | table accountExpires endDate x
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...