Splunk Search

convert date time to epoch time for sorting

smolcj
Builder

How to convert the date and time in the below format to epoch time?
201303140216
yyyymmddHHMM
here hour and minute is in 12 hours clock, so the time may be 02:16PM
tried converting it using
time=strptime(mytime,"%Y%m%d%I%M")
not seems to be working properly...
please help
Thank You

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

If your time is on a 12-hour clock you will need to list AM or PM in your date string, and read that into strptime with %p, without that the hour is ambiguous.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

If your time is on a 12-hour clock you will need to list AM or PM in your date string, and read that into strptime with %p, without that the hour is ambiguous.

smolcj
Builder

Thanks martin.. I think I have to search some other field for sorting.. Thank you for your help .

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

How do you expect the conversion to epoch to work then? Guessing?

If you have sufficient data and a known starting point you could extrapolate AM/PM over a stream of events based on the rollover from 11 to 12, flipping the A/P every time - that's not robust though.

smolcj
Builder

unfortunately i dont have AM or PM specification in the field :disappointed_face:

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...