Splunk Search

Time coversion not working

nwoolley
Engager

index=asg Process_name=WLR_22-15_Rating earliest =-5m | convert timeformat="%d-%M-%Y-%H:%M:%S" mktime(start_dtm) mktime(end_dtm) | eval duration=end_time-start_time | table duration

Data
15-OCT-2019-11:25:02,Process_name=WLR_22-15_Rating,start_dtm=14-OCT-2019-22:15:40,end_dtm=15-OCT-2019-00:47:36,errors=10503,work_done=651649

Not sure why the above is failing any help would be grateful thanks

Tags (1)
0 Karma

nwoolley
Engager

Perfect answer very quick thank you

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@nwoolley

Can you please try this?

index=asg Process_name=WLR_22-15_Rating earliest =-5m 
| eval start_time=strptime(start_dtm,"%d-%b-%Y-%H:%M:%S"), end_time=strptime(end_dtm,"%d-%b-%Y-%H:%M:%S") 
| eval duration=end_time-start_time 
| table duration

Example:

| makeresults 
| eval _raw="15-OCT-2019-11:25:02,Process_name=WLR_22-15_Rating,start_dtm=14-OCT-2019-22:15:40,end_dtm=15-OCT-2019-00:47:36,errors=10503,work_done=651649" 
| extract 
| eval start_time=strptime(start_dtm,"%d-%b-%Y-%H:%M:%S"), end_time=strptime(end_dtm,"%d-%b-%Y-%H:%M:%S") | eval duration=end_time-start_time | table duration
0 Karma

nwoolley
Engager

Perfect answer very quick thank you

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

Great @nwoolley

Please upvote and accept this answer to close this question.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...