Splunk Search

how to calculate starttime and Endtime duration

babukumarreddy
Loves-to-Learn Lots

how to calculate starttime and Endtime duration

|08-feb-2019 01:30:18|08-feb-2019 01:30:28

Tags (1)
0 Karma

chrisyounger
SplunkTrust
SplunkTrust

Try this: |eval d1 = strptime(starttime, "%d-%b-%Y %H:%M:%S") | eval d2 = strptime(endtime, "%d-%b-%Y %H:%M:%S") | eval duration_in_seconds = d1 - d2

Hope this helps

0 Karma

pkarpushin
Path Finder

Hi @babukumarreddy ,

If I get correctly whay you mean, you have a set of events and you need to calculate the time delta between the earliest and latest event.
You could use stast command:

<your main search here> | stats first(_time) as End, last(_time) as Start | eval Duration=End-Start | ....

But it would be better if you give more detailed description of your goal.

0 Karma

babukumarreddy
Loves-to-Learn Lots

Hi Pkarpushin

actually iam new to splunk

in my logs starttime and endtime is there need to calculate duration
starttime endtime
|08-feb-2019 01:30:18|08-feb-2019 01:30:28

fieldnames are starttime and endtime

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...