Splunk Search

how to calculate the starttime and endtime between duration ?

babukumarreddy
Loves-to-Learn Lots

actually iam new to splunk

in my logs starttime and endtime is there need to calculate duration
starttime endtime
|01-feb-2019 01:30:18|01-feb-2019 01:30:28

fieldnames are starttime and endtime

Tags (1)
0 Karma
1 Solution

chrisyounger
SplunkTrust
SplunkTrust

Try this: |eval d1 = strptime(starttime, "%d-%b-%Y %H:%M:%S") | eval d2 = strptime(endtime, "%d-%b-%Y %H:%M:%S") | eval duration_in_seconds = d1 - d2

Hope this helps

View solution in original post

0 Karma

chrisyounger
SplunkTrust
SplunkTrust

Try this: |eval d1 = strptime(starttime, "%d-%b-%Y %H:%M:%S") | eval d2 = strptime(endtime, "%d-%b-%Y %H:%M:%S") | eval duration_in_seconds = d1 - d2

Hope this helps

0 Karma

babukumarreddy
Loves-to-Learn Lots

Hi Chrisyongerjds

its not working

index="starttime"|eval d1 = strptime(starttime, "%d-%m-%Y %H:%M:%S") | eval d2 = strptime(endtime, "%d-%m-%Y %H:%M:%S") | eval duration_in_seconds = d1 - d2|table starttime endtime duration_in_seconds

0 Karma

babukumarreddy
Loves-to-Learn Lots

ignore above comment
it's working

thank you Chrisyongerjds

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...