I would like to know if the results of "strptime" are in seconds?
index=main sourcetype=access_combined host=vsalinux06
| eval desired_time=strptime(req_time, "%d/%B/%Y:%I:%M:%S %z")
| table method uri desired_time
Check this link for more details
It is a Unix timestamp
View solution in original post