Hey 👋, I'm trying to get the time difference between when an event was received and a string representation of the time in the event. Here's an example of the event: {
"action": "created",
"alert": {
"number": 818,
"created_at": "2021-11-16T21:52:12Z",
"url": "https://somewebsite.com"
}
} The issue is the conversion of the time in "alert.created_at" from string to epoch. Once I'm able to get the epoch representation, calculating the difference from _time is easy. I'm working off this eval statement, but cant get it to work: | eval strtime=strptime(alert.created_at, "%Y-%m-%dT%H:%M:%SZ") | table strtime Any thoughts? Thanks!
... View more