to_timestamp

Cortex XDR XQL to_timestamp() function converts an integer to a timestamp.

Synopsis

to_timestamp (<
integer
>, <
units
>)

Description

The
to_timestamp()
function converts an integer to a timestamp. This function requires a
units
value, which indicates whether the integer represents seconds, milliseconds, or microseconds since the Unix epoch. Supported values are:
  • SECONDS
  • MILLIS
  • MICROS
For example:
dataset = xdr_data | filter story_publish_timestamp != null | alter ts = to_timestamp(story_publish_timestamp, "MILLIS") | fields ts

Recommended For You