Splunk Search

Subtract Dates/Time

schufi01
Path Finder

Hi,

can somebody explain, why I dont get any results?

index=... 
| eval Timestamp=strftime(_time,"%d-%m-%Y %H:%M:%S")
| eval CurrentTime=strftime(now(),"%d-%m-%Y %H:%M:%S")
| eval NotUsedFor=(CurrentTime-Timestamp)
| chart max(NotUsedFor) by host

I want a chart that shows the difference of the CurrentTime and the Timestamp

 

Labels (2)
0 Karma
1 Solution

scelikok
Influencer

Hi @schufi01,

You must make calculation before formatting the timestamps;

index=... 
| eval NotUsedFor=(now()-_time)
| chart max(NotUsedFor) by host
If this reply helps you an upvote is appreciated.

View solution in original post

scelikok
Influencer

Hi @schufi01,

You must make calculation before formatting the timestamps;

index=... 
| eval NotUsedFor=(now()-_time)
| chart max(NotUsedFor) by host
If this reply helps you an upvote is appreciated.

View solution in original post