Skip to content

Instantly share code, notes, and snippets.

@kitwalker12
Created January 5, 2016 02:25
Show Gist options
  • Save kitwalker12/2a8b50f80ea265282505 to your computer and use it in GitHub Desktop.
Save kitwalker12/2a8b50f80ea265282505 to your computer and use it in GitHub Desktop.
Splunk use modified time for query + dedup ascending time
eval _time=strptime(some_time_field,"%Y-%m-%dT%H:%M:%S%z")
dedup source sortby +_time
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment