Splunk Search

help on epoch time format number

jip31
Motivator

hi

I would like to transform the epoch time number below in a standard format date

1546284113.000000

could you please help me?

Tags (1)
0 Karma
1 Solution

sdchakraborty
Contributor

Hi,

Is this what you looking for?

|  makeresults 
| eval date = 1546284113.000000
| eval formatted_date = strftime(date,"%d-%m-%Y %H:%M:%S")

for more formatting options please have a look at the below link,

https://docs.splunk.com/Documentation/Splunk/7.2.3/SearchReference/Commontimeformatvariables

Sid

View solution in original post

0 Karma

sdchakraborty
Contributor

Hi,

Is this what you looking for?

|  makeresults 
| eval date = 1546284113.000000
| eval formatted_date = strftime(date,"%d-%m-%Y %H:%M:%S")

for more formatting options please have a look at the below link,

https://docs.splunk.com/Documentation/Splunk/7.2.3/SearchReference/Commontimeformatvariables

Sid

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...