Search Reference

 


reltime

reltime

Synopsis

Creates a relative time field, called 'reltime', and sets it to a human readable value of the difference between 'now' and '_time'.

Syntax

reltime

Description

Sets the 'reltime' field to a human readable value of the difference between 'now' and '_time'. Human-readable values look like "5 days ago", "1 minute ago", "2 years ago", etc.

Examples

Example 1: Add a reltime field.

... | reltime

See also

convert

Answers

Have questions? Visit Splunk Answers and see what questions and answers the Splunk community has using the reltime command.

This documentation applies to the following versions of Splunk: 4.1.5 , 4.1.6 , 4.1.7 , 4.1.8 , 4.2 , 4.2.1 , 4.2.2 , 4.2.3 , 4.2.4 , 4.2.5 , 4.3 , 4.3.1 , 4.3.2 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!