You've mixed functions and fields.
_time is a field that says when an event happened.
info_min_time and info_max_time are fields added by the addinfo
command. These fields are the lower and upper bounds of the search. They can be used to define the time period of a report, for instance.
The now()
and time()
functions both return the current time of day. time()
includes microseconds whereas now()
is the time in seconds. Both can be used in calculations to determine how old an event is.
The strptime()
function converts a timestamp string ("2016-06-05", for example) into epoch (integer) form. This is the only way to do calculations with times.
The strftime()
function is the inverse of strptime()
. It converts a timestamp from epoch form into a human-readable string.
You've mixed functions and fields.
_time is a field that says when an event happened.
info_min_time and info_max_time are fields added by the addinfo
command. These fields are the lower and upper bounds of the search. They can be used to define the time period of a report, for instance.
The now()
and time()
functions both return the current time of day. time()
includes microseconds whereas now()
is the time in seconds. Both can be used in calculations to determine how old an event is.
The strptime()
function converts a timestamp string ("2016-06-05", for example) into epoch (integer) form. This is the only way to do calculations with times.
The strftime()
function is the inverse of strptime()
. It converts a timestamp from epoch form into a human-readable string.