Hi,
I am giving the following query :
| inputlookup file.csv | eval CT="1/24/2013 6:54" | convert timeformat="%m/%d/%Y %T" mktime("DATE LOGGED") mktime(CT) | eval duration=("DATE LOGGED"-CT)
and it is giving me :
Error in 'eval' command: Typechecking failed. '-' only takes numbers.
I simply want to find out the difference betwen the time given in one field called "DATE LOGGED" and today's date i.e., "1/24/2013" ( the date when I run my query )
Please help
I don't know if Splunk can operate on epoch-formatted times. What I would try is to convert epochs to seconds or another duration format and then do the math. Maybe it isn't a fancy solution, but it could work.
That's seems good, But How to do that ?
Any Example would be highly appreciated