Splunk Search

How to leave date (in a field) is before today?

KH
Engager

I'm extremely new to Splunk and finding learning SPL very frustrating.

I'm trying to look for windows log on events/ attempted log ons by leavers accounts after their last working day. How do i say where a specific field (the last working day) is before todays date. 

The last working day field which I'm pulling from a separate index is in the following format "2020-02-28 00:00:00.0"

 

 

Labels (2)
0 Karma

KH
Engager

thank you! 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You need to parse the last working day into an epoch time, then compare it to the epoch time for the start of the current day.

| where strptime(last_working_day_field,"%Y-%m-%d %H:%M:%S") < relative_time(now(),"@d")
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

[Puzzles] Solve, Learn, Repeat: Nested loops in Event Conversion

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...