Splunk Search

How to comparing 2 date fields and create a third with the difference

ajdyer2000
Path Finder

Event_Reported_Time Comment_Date Diff
7/21/2016 7/22/2016 1
7/24/2016 7/29/2016 5
8/16/2016 8/25/2016 9

Tags (2)
0 Karma

sbbadri
Motivator

| makeresults | eval Event_Reported_Time="7/21/2016" | eval Comment_Date="7/22/2016" | eval Event_Reported_Time = strptime(Event_Reported_Time,"%m/%d/%Y") | eval Comment_Date = strptime(Comment_Date,"%m/%d/%Y") | eval diff_time = Comment_Date - Event_Reported_Time | eval diff_days = diff_time / 86400

0 Karma

woodcock
Esteemed Legend

Like this:

... | foreach * [eval <<FIELD>>_Epoch = strptime(<<FIELD>>, "%m/%d/%Y")]
| eval Diff = (Comment_Date_Epoch - Event_Reported_Time_Epoch) / (60*60*24)
0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...