Splunk Search

convert time field

gdavid
Path Finder

i have the last sync time for my activesync clients going to splunk via powershell input.
ex: LastSyncAttemptTime = 04/07/2016 21:49:08
this produces a text field that is not sortable or useable.
i tried to convert it using:

| eval lastSync=strptime(LastSyncAttemptTime,"%x %T") | table lastSync

with no luck. i have tired numerous variations of %codes to list the date and time, and a few variations produce a decimal value.

my end goal here is to look for clients that last synced over 30 days ago.

any ideas?

thanks

Gd

Tags (1)
0 Karma
1 Solution

MuS
Legend

Hi gdavid,

you can try this instead:

| eval lastSync=strptime(LastSyncAttemptTime, "%m/%d/%Y %H:%M:%S")

Hope this helps ...

cheers, MuS

View solution in original post

MuS
Legend

Hi gdavid,

you can try this instead:

| eval lastSync=strptime(LastSyncAttemptTime, "%m/%d/%Y %H:%M:%S")

Hope this helps ...

cheers, MuS

gdavid
Path Finder

this seems to be working to generate the field in human readable format

lastSync=strftime(strptime(LastSyncAttemptTime, "%m/%d/%Y %H:%M:%S"),"%m/%d/%y %H:%M:%S")

what i realized is to finish the rest of the search it was easier to leave it in epoch time. use this for now:

| eval lastSync=strptime(LastSyncAttemptTime, "%m/%d/%Y %H:%M:%S") | eval lastsyncbad = relative_time(now(), "-30d" ) | where lastSync < lastsyncbad

there might be a more effective method but this works.

0 Karma

gdavid
Path Finder

that yields:

LastSyncAttemptTime
04/08/2016 07:19:46

lastSync
1460114386.000000

which looks like it converted it into epoch time. convert again?

0 Karma

MuS
Legend

What is your intention / use case? please explain a bit further otherwise no one will be able to help you in the end 😉

0 Karma

gdavid
Path Finder

from above: my end goal here is to look for clients that last synced over 30 days ago.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...