To compare two times in Splunk you must first convert them into epoch (integer) form. Do that using the strptime function.
| eval created = strptime(CREATED_TS, "%Y%M%D%H%M%S.%3N")
| eval current = strptime(CURRENT_TIMESTAMP, "%Y%M%D%H%M%S")
| eval diff = current - created
To compare two times in Splunk you must first convert them into epoch (integer) form. Do that using the strptime function.
| eval created = strptime(CREATED_TS, "%Y%M%D%H%M%S.%3N")
| eval current = strptime(CURRENT_TIMESTAMP, "%Y%M%D%H%M%S")
| eval diff = current - created