Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Find difference between time now and last event time

$
0
0
I am not sure why I am not getting results with this query, any suggestions? index= ______ | stats max(_time) as last_event | eval timenow=strftime(now(), "%Y-%m-%d %H:%M:%S.%3N") | eval last_event=strftime('last_event', "%Y-%m-%d %H:%M:%S.%3N") | eval diff = tostring((timenow - last_event), "duration") | table diff

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>