Hi
I would like to know if the results of "strptime" are in seconds?
index=main sourcetype=access_combined host=vsalinux06
|eval kb=bytes/1024
| eval desired_time=strptime(req_time, "%d/%B/%Y:%I:%M:%S %z")
| table method uri desired_time
It is a Unix timestamp
Hi
Check this link for more details
https://docs.splunk.com/Documentation/Splunk/7.3.0/SearchReference/DateandTimeFunctions