Splunk Search

Convert epoch time to days, hours minutes, seconds

danielrusso1
Path Finder

I would like to take a large epoch time (8492963) and convert it into Days:Hours:Minutes:Seconds (for example 98:07:09:23).

Is there a command to execute this, or does it all need to be done using simple math?

Tags (2)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You're talking about a time interval in seconds that needs to be converted into readable format? Try this:

... | eval readable = tostring(interval_in_seconds, "duration")

For your example that will set readable to "98+07:09:23"

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You're talking about a time interval in seconds that needs to be converted into readable format? Try this:

... | eval readable = tostring(interval_in_seconds, "duration")

For your example that will set readable to "98+07:09:23"

danielrusso1
Path Finder

ah, of course. thanks!

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...