Splunk Search

## Why is the relative_time not converting +24y? Is there a limitation in the function?

Motivator

Hi Splunkers,

Why the relative_time function is not converting +24y? any reason? Any way to achieve this?

``````|stats count | eval next_time=relative_time(now(),"+24y")
``````

Is there any limitation in relative_time function?

Cheers!!!

V
Tags (4)
1 Solution
Influencer

It seems that relative_time (at least on 6.2.0) is limited by the Year 2038 problem: http://en.wikipedia.org/wiki/Year_2038_problem

Check this out, this works:

``````noop | stats count | eval _time=relative_time(now(),"+24y@y+18d+3h+14m+7s")
``````

But this doesn't:

``````noop | stats count | eval _time=relative_time(now(),"+24y@y+18d+3h+14m+8s")
``````

But this does:

``````noop | stats count | eval _time=relative_time(now(),"+24y@y+18d+3h+14m+7s")+1
``````
Path Finder

is there an update on this issue? what's an alternative solution?

Path Finder

we've fixed the issue by using good ol strptime and strftime

Influencer

It seems that relative_time (at least on 6.2.0) is limited by the Year 2038 problem: http://en.wikipedia.org/wiki/Year_2038_problem

Check this out, this works:

``````noop | stats count | eval _time=relative_time(now(),"+24y@y+18d+3h+14m+7s")
``````

But this doesn't:

``````noop | stats count | eval _time=relative_time(now(),"+24y@y+18d+3h+14m+8s")
``````

But this does:

``````noop | stats count | eval _time=relative_time(now(),"+24y@y+18d+3h+14m+7s")+1
``````
Influencer

For those following along at home... as it's still a problem, I logged Case 468033 for this.

Get Updates on the Splunk Community!

#### What’s new on Splunk Lantern in August

This month’s Splunk Lantern update gives you the low-down on all of the articles we’ve published over the past ...

#### Welcome to the Future of Data Search & Exploration

You have more data coming at you than ever before. Over the next five years, the total amount of digital data ...

#### This Week's Community Digest - Splunk Community Happenings [8.3.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...