| eval "Last Logon"=strftime(strptime(LastLogon, "%Y-%m-%dT%H:%M:%S.%QZ"),"%Y%m%d %H:%M:%S")
| eval lastLogon=strptime(LastLogon, "%Y-%m-%dT%H:%M:%S.%QZ") Sorry about not having a better explanation. "Last Logon" and "lastLogon" are being generated from a field "LastLogon" which I hope or assume is in the original data set. "Last Logon" is a nested strptime inside a strftime. The strptime takes and human readable format and converts to epoch, while the strftime will take epoch and convert to human readable. The nested function here essentially converts the format from one human readable to another human readable. There are easier methods but if it was working maybe don't change it until your skill level jumps. "lastLogon" just takes the human readable format and converts to epoch(Unix) time - which makes duration calculations much easier. Check that "LastLogon" field is still there and that the format still matches the "xxxx-xx-xxTxx:xx:xx.xxxZ" that the strptime command is configured to expect. Also check to see if the time shift you are experience can be explain by the delta in your local time zone (either personal setting, or that of the Search Head). It expects the raw data from the field to be in Zulu time.
... View more