Splunk Search

Time Difference problem

abhayneilam
Contributor

Hi,

I am giving the following query :

| inputlookup file.csv | eval CT="1/24/2013 6:54" | convert timeformat="%m/%d/%Y %T" mktime("DATE LOGGED") mktime(CT) | eval duration=("DATE LOGGED"-CT)

and it is giving me :

Error in 'eval' command: Typechecking failed. '-' only takes numbers.

I simply want to find out the difference betwen the time given in one field called "DATE LOGGED" and today's date i.e., "1/24/2013" ( the date when I run my query )

Please help

Tags (3)
0 Karma

javo
Explorer

I don't know if Splunk can operate on epoch-formatted times. What I would try is to convert epochs to seconds or another duration format and then do the math. Maybe it isn't a fancy solution, but it could work.

0 Karma

abhayneilam
Contributor

That's seems good, But How to do that ?

Any Example would be highly appreciated

0 Karma
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...