...hich I have used to successfully convert a string field ('due_at') representing an UTC value (although formatted without the time-zone designation at the end), to an abbreviated notation (month-day-y...
...atest$ into the form and get the epoch back. I want to get a human readable dateformat so the user can see what the date range is for each panel.
Any assistance would be appreciated.
...efault|OK|0|100
The first field is the timestamp, that only has the hour:minute:second:milisecond (no date). Then, separated by the "|" character, the rest of the fields. These fields are d...
...poch time so I can perform some date calculations.
So I've been looking at the Splunk documentation here and I thought I'd understood the variables I need to use and then convert and I put together t...
I'm dealing with bash_history files in the following format. I would like to extract the timestamp and use that as the event timestamp, but I'm having some issues doing so.
#1579207583
whoami
#1...
...o get a wider data set than the one selected by the user. And then using variables in the search to restore time boundaries to initial selection that I use for some specific calculation (not shown i...
I have a single dataset which contains a couple of variables which are time (date) based. The format for all of them is the same.
I am interested in having a count of two different date types....
...2
because the search work only on first case.
I try something this to do earliest and latest as variables:
| makeresults
| eval time = relative_time(now(),"-h@w1")
| eval format...
...hould give me (11/14/17 7:40:00.000 AM), but Splunk just won't recognize the 3 digit format.
I've tried every combination of Date\Timeformatvariables I can think of and even made an attempt at a c...
I have a form that allows the user to input a text token. The idea is the user will input dateandtime information. I then would like to have a search on the form run starting 10 minutes before t...