• Todd Waller

Splunk - Quick Tip - Find number of days between date and now()

Hello Again Everyone!

Here’s something I ran into not that long ago. So I found the need to calculate the number of days between a day and now, now being the time I ran the search or when a report was run.

I have a field called "Step Due Date" formatted as "%Y-%m-%d %H:%M:%S.%6N"

Basically the Step Due Date is a date a step in a workflow is due. What I would like to do is find the number for days remaining between that date and today(when the report/search is run).

It’s a pretty easy few stanzas to get all of the data in the right format and calculated correctly. There may even be better ways to accomplish this but, for my needs this easily worked. Feel free to tweak the round function to be more exact, just an example:

| eval dateDue=strptime('Step Due Date', "%Y-%m-%d %H:%M:%S.%6N")| eval days = round((now()-dateDue)/86400)

Just a fun little exercise in quick calculations.

Thanks for the quick read!


33 views0 comments

Recent Posts

See All

Do you need to dedup when using stats?

I had to do some casual counting of sourcetypes today. In the process I was trying to decide if I needed to dedup before going to stats. It seemed to me a dedup would, in theory, pass less data to sta

How do I learn Splunk administration?

Had an old coworker hit me up a week ago. He took a job as a SOC analyst where part of his job is going to be supporting Splunk. He's a smart guy but Splunk is more complex than it looks. Given I've a