SPL
Convert non timestamp time to Epoch
Description
Scenario:
You have a non timestamp field that you need to convert to epoch time to perform statistics on within splunk.
Here's how you do it:
4 4
your search goes here |eval Epoch_Time=strptime(Field_Date, "%Y-%m-%d %H:%M:%S")
Comments
0 total
Be the first to comment on this SPL.
Leave a comment
You must log in to post a comment.