Splunk Enterprise Security

How may I change MM/DD/YYYY HH:MM:SS to epoch time?

jsven7
Communicator

Situation:
- I have some records with a human readable field "Creation Date" (MM/DD/YYYY HH:MM:SS).
- I'd like to sort by "Creation Date"

Problem:
- The sort command does not appear to work. I believe this is because it needs to be in epoch time to make the calculation.

Proposed Solution:
- Convert the field to epoch and run the sort command against the data set using the new epoch field.

0 Karma
1 Solution

vnravikumar
Champion

Hi

Check this

| makeresults 
| eval "Creation Date"="03/26/2020 13:56:12" 
| eval epoch=strptime('Creation Date',"%m/%d/%Y %H:%M:%S")

View solution in original post

vnravikumar
Champion

Hi

Check this

| makeresults 
| eval "Creation Date"="03/26/2020 13:56:12" 
| eval epoch=strptime('Creation Date',"%m/%d/%Y %H:%M:%S")

jsven7
Communicator

@vnravikumar - thank you!

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...