Splunk Search

Why is the relative_time not converting +24y? Is there a limitation in the function?

vasanthmss
Motivator

Hi Splunkers,

Why the relative_time function is not converting +24y? any reason? Any way to achieve this?

|stats count | eval next_time=relative_time(now(),"+24y") 

Is there any limitation in relative_time function?

Cheers!!!

V
1 Solution

acharlieh
Influencer

It seems that relative_time (at least on 6.2.0) is limited by the Year 2038 problem: http://en.wikipedia.org/wiki/Year_2038_problem

Check this out, this works:

noop | stats count | eval _time=relative_time(now(),"+24y@y+18d+3h+14m+7s")

But this doesn't:

noop | stats count | eval _time=relative_time(now(),"+24y@y+18d+3h+14m+8s")

But this does:

noop | stats count | eval _time=relative_time(now(),"+24y@y+18d+3h+14m+7s")+1

View solution in original post

cabauah
Path Finder

is there an update on this issue? what's an alternative solution?

0 Karma

cabauah
Path Finder

we've fixed the issue by using good ol strptime and strftime

acharlieh
Influencer

It seems that relative_time (at least on 6.2.0) is limited by the Year 2038 problem: http://en.wikipedia.org/wiki/Year_2038_problem

Check this out, this works:

noop | stats count | eval _time=relative_time(now(),"+24y@y+18d+3h+14m+7s")

But this doesn't:

noop | stats count | eval _time=relative_time(now(),"+24y@y+18d+3h+14m+8s")

But this does:

noop | stats count | eval _time=relative_time(now(),"+24y@y+18d+3h+14m+7s")+1

acharlieh
Influencer

For those following along at home... as it's still a problem, I logged Case 468033 for this.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...