Creates a relative time field, called 'reltime', and sets this field to a human readable value of the difference between 'now' and '_time'. Human-readable values look like "5 days ago", "1 minute ago", "2 years ago", and so on.
Adds a field called
reltime to the events returned from the search.
... | reltime
Have questions? Visit Splunk Answers and see what questions and answers the Splunk community has using the reltime command.
This documentation applies to the following versions of Splunk Cloud™: 6.6.3, 7.0.2, 7.0.0, 7.0.3, 7.0.5, 7.0.8, 7.1.3, 7.1.6, 7.2.3, 7.2.4