Splunk Search

calculate duration on a custom time stamp

twilishyflutter
New Member

my time stamps are in %H:%M format. one of which is a custom time stamp from my json file.
is there a way i can calculate the duration with this timestamp

Tags (1)
0 Karma

cmerriman
Super Champion

try something like:

| eval newTime=strptime(timeStr, "%H:%M")

to convert the timestamps and then you should be able to use that in an eval to substract timestamps.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...