Splunk Search

Convert epoch time to days, hours minutes, seconds

danielrusso1
Path Finder

I would like to take a large epoch time (8492963) and convert it into Days:Hours:Minutes:Seconds (for example 98:07:09:23).

Is there a command to execute this, or does it all need to be done using simple math?

Tags (2)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You're talking about a time interval in seconds that needs to be converted into readable format? Try this:

... | eval readable = tostring(interval_in_seconds, "duration")

For your example that will set readable to "98+07:09:23"

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You're talking about a time interval in seconds that needs to be converted into readable format? Try this:

... | eval readable = tostring(interval_in_seconds, "duration")

For your example that will set readable to "98+07:09:23"

danielrusso1
Path Finder

ah, of course. thanks!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...