Splunk Search

## how to calculate the starttime and endtime between duration ?

Loves-to-Learn Lots

actually iam new to splunk

in my logs starttime and endtime is there need to calculate duration
starttime endtime
|01-feb-2019 01:30:18|01-feb-2019 01:30:28

fieldnames are starttime and endtime

Try this: `|eval d1 = strptime(starttime, "%d-%b-%Y %H:%M:%S") | eval d2 = strptime(endtime, "%d-%b-%Y %H:%M:%S") | eval duration_in_seconds = d1 - d2`

Hope this helps

Hi Chrisyongerjds

its not working

index="starttime"|eval d1 = strptime(starttime, "%d-%m-%Y %H:%M:%S") | eval d2 = strptime(endtime, "%d-%m-%Y %H:%M:%S") | eval duration_in_seconds = d1 - d2|table starttime endtime duration_in_seconds

ignore above comment
it's working

thank you Chrisyongerjds

