| makeresults | eval field1="2022-08-27T02:00:00" | eval field2=strptime(field1,"%Y-%m-%dT%H:%M:%S") | eval field3=relative_time(field2,"+8h") | eval field4=strftime(field3,"%a %b %d %H:%M:%S.%Z %Y") | table field1 field2 field3 field4 First , using "strptime" function to transform String time "2022-08-27T02:00:00" to Unix timestamp field2 base on my time zone( My time zone setting is UTC+8, Splunk consider the time zone of String time as UTC+8, so the Unix timestamp value is 1661536800). You can check your time zone setting as below. Second, I know the time zone of String time is UTC not UTC+8, so I use "relative_time" function to add 8 hous to field2 , then I get field3 Finally, using "strftime" function to transform Unix timestamp to human readable format field 4 The date and time format variables I used , you can find them in this link Date and time format variables - Splunk Documentation Hope my answer can help you.
... View more