Well it's a difficult conversion for me, anyway.
Here's the field: dateTime=Fri Jan 18 17:11:55 GMT+00:00 2013
I want to convert it to seconds since the epoch so I can do a date comparison.
I don't think there's a way for Splunk to recognize the tz offset as "+00:00" so first I transform that to "+0000".
eval dtFormatted=replace(dateTime, ":", "") |
eval dtSeconds=strptime(dtFormatted, "%a %b %d %H%M%S %Z%:z %Y")
In my search results "dtFormatted" is discovered and I've verified it's properly formatted but "dtSeconds" is not discovered.
What am I doing wrong? Why can't I convert this string to seconds?
... View more