Splunk Search

time difference issue

changwoo
Communicator

start_time = > 2014-02-13T22:57:15+0900

end_ time = > 2014-02-13T23:59:54+0900

how can i get the time difference ??

i tried

convert timeformat="%Y/%m/%d %H:%M:%S" mktime(start_time) AS StartTime_epoch mktime(end_time) AS ResolvedTime_epoch | eval total=round((ResolvedTime_epoch-StartTime_epoch)/60/60/24)

Tags (2)
0 Karma
1 Solution

kristian_kolb
Ultra Champion

Try this,

your_base_search 
| eval epoch_st = strptime(start_time, "%Y-%m-%dT%H:%M:%S%z") 
| eval epoch_et = strptime(end_time, "%Y-%m-%dT%H:%M:%S%z")
| eval epoch_diff = epoch_et - epoch_st
| eval dur=tostring(epoch_diff, "duration")

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions

/K

View solution in original post

kristian_kolb
Ultra Champion

Try this,

your_base_search 
| eval epoch_st = strptime(start_time, "%Y-%m-%dT%H:%M:%S%z") 
| eval epoch_et = strptime(end_time, "%Y-%m-%dT%H:%M:%S%z")
| eval epoch_diff = epoch_et - epoch_st
| eval dur=tostring(epoch_diff, "duration")

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions

/K

kristian_kolb
Ultra Champion

oh well, if your fields are actually called start_time and end_time, the new fields should come out fine. However, they do not show in the event text (_raw), but you can use them in tables, charts, stats etc.

0 Karma

changwoo
Communicator

i tried but epoch_st epoch_et, epoch_diff , dur field is not comming out ..

it's showing the _raw data...

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...