Creates a relative time field, called 'reltime', and sets this field to a human readable value of the difference between 'now' and '_time'. Human-readable values look like "5 days ago", "1 minute ago", "2 years ago", and so on.
reltime command is a distributable streaming command. See Command types.
Adds a field called
reltime to the events returned from the search.
... | reltime
Have questions? Visit Splunk Answers and see what questions and answers the Splunk community has using the reltime command.
This documentation applies to the following versions of Splunk Cloud™: 7.0.8, 7.0.11, 7.0.13, 7.1.3, 7.1.6, 7.2.3, 7.2.4, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 8.0.0, 8.0.1, 8.0.2001