Overview

This three-hour course is for power users who want to become experts at using time in searches. Topics will focus on searching and formatting time in addition to using time commands and working with time zones.

Limited time offer: Splunk Core Certified Power User certification at 30% discount!

Skills Covered

Please refer to course overview.

Prerequisites

To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge:

  • Intro to Splunk
  • Using Fields
  • Visualizations

Target Audience

  • Users/Analysts
  • Administrators
  • Engineers

Course Curriculum

Module 1: Searching with Time

  • Understand the_time field and timestamps
  • View and interact with the event Timeline
  • Use the earliest and latest time modifiers
  • Use the bin command with the _time field

Module 2: Formatting Time

  • Use various date and time eval functions to format time

Module 3: Using Time Commands

  • Use the timechart command
  • Use the timewrap command

Module 4: Working with Time Zones

  • Understand how time and timezones are represented in your data
  • Determine the time zone of your server
  • Use strftime to correct timezones in results

Dates & Locations

Let’s make it work for you

Can’t find a date that fits? Need to train your whole team? Looking for a discount?
Speak to one of our learning experts today.

July 27, 2026 - July 27, 2026

Location: Online
Modal: VILT
Availability: TBC

September 21, 2026 - September 21, 2026

Location: Online
Modal: VILT
Availability: TBC
Trainocate exam and cert

Exam & Certification

This course is not associated with any Certification.

Training & Certification Guide

Frequently Asked Questions

Speak to a Training Consultant

All courses are HRD Claimable.
Get in touch with our team via the form or WhatsApp us on +6011-5119 6631

Preferred mode of training
Checkboxes