I'm able to create the following calculated field in the Search app.
.... | eval KCQueueDuration = (strptime(KCQStartDate." ".KCQStartTime, "%Y-%m-%d %H:%M:%S")) - (strptime(KCQEndDate." ".KCQEndTime, "%Y-%m-%d %H:%M:%S"))
However, I'm not able to get it to work when I create this field using the Splunk Web App (Settings->Fields->Calculated Fields) or editing the props.conf file. The field doesn't show up in the list of interesting fields, when I just search for all events for the source type. If I use this process to create a calculated field that just contains 1 of the strptime functions, it appears in the list of interesting fields.
Below is an example of the event data.
KCUID=905252z911311o,KCQStartDate=2016-01-06,KCQStartTime=15:19:46,KCQEndDate=2016-01-06,KCQEndTime=15:19:48
I couldn't find anything indicating that this expression is invalid in props.conf. Is this a known limitation of calculated fields in props.conf?
... View more