Getting Data In

Calculate difference between 2 timestamps in days?

AzmathShaik
Path Finder

i 'm trying to calculate the difference between two timestamps in number of days. here is my query
base_search
| eval intime = strptime(minTime, "%Y-%m-%dT%H:%M:%S")
| eval outtime = strptime(maxTime, "%Y-%m-%dT%H:%M:%S")
| eval timediffindays = tostring((outtime - intime), "duration")

my timestamp filed looks like "2019-09-23T18:51:52+0000"

my outcome looks like " 367+01:43:52.000000"

i am expecting to see the results in number of days

Thanks
Azmath

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What tostring gave you is a number of days. It also expressed the remainder in terms of hours, minutes, and seconds.
If you only want days, try this:

| eval intime = strptime(minTime, "%Y-%m-%dT%H:%M:%S")
| eval outtime = strptime(maxTime, "%Y-%m-%dT%H:%M:%S")
| eval timediffindays = (outtime - intime)/86400
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...