Splunk Search

calculate duration on a custom time stamp

twilishyflutter
New Member

my time stamps are in %H:%M format. one of which is a custom time stamp from my json file.
is there a way i can calculate the duration with this timestamp

Tags (1)
0 Karma

cmerriman
Super Champion

try something like:

| eval newTime=strptime(timeStr, "%H:%M")

to convert the timestamps and then you should be able to use that in an eval to substract timestamps.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...