now
You can use now to calculate relative times, filter events by recency, and compute the age of records in your dataset.
Use it when you want to:
- Filter events to a recent time window.
- Calculate how long ago an event occurred.
- Add the current timestamp to query output for audit or comparison purposes.
Usage#
Syntax#
now([offset])Parameters#
| Name | Type | Description |
|---|---|---|
| offset | timespan |
Optional: A timespan added to the current UTC clock time. Default is 0. |
Returns#
The current UTC clock time as a datetime. All references to now() within a single statement return the same value.
Use case examples#
Calculate the age of each request in hours to understand how recent events are.
Query
['sample-http-logs']
| extend age_hours = datetime_diff('hour', now(), _time)
| project _time, age_hours, method, status
| take 10Output
| _time | age_hours | method | status |
|---|---|---|---|
| 2025-01-15T10:00:00Z | 48 | GET | 200 |
| 2025-01-15T10:05:00Z | 47 | POST | 201 |
| 2025-01-15T10:10:00Z | 47 | GET | 500 |
This query calculates how many hours ago each HTTP request occurred by comparing the event time to the current time.
Find traces from the last 5 minutes to monitor recent activity by service.
Query
['otel-demo-traces']
| where _time > now(-5m)
| summarize trace_count = count() by ['service.name']Output
| service.name | trace_count |
|---|---|
| frontend | 120 |
| cart | 85 |
| checkout | 42 |
This query filters traces to those generated in the last 5 minutes and counts them by service name.
Show the current time alongside each failed request to calculate how many minutes have passed since the event.
Query
['sample-http-logs']
| where toint(status) >= 400
| extend current_time = now()
| extend time_since = datetime_diff('minute', current_time, _time)
| project _time, current_time, time_since, status, uri
| take 10Output
| _time | current_time | time_since | status | uri |
|---|---|---|---|---|
| 2025-01-15T10:00:00Z | 2025-01-17T10:00:00Z | 2880 | 403 | /admin |
| 2025-01-15T10:05:00Z | 2025-01-17T10:00:00Z | 2875 | 500 | /api/users |
| 2025-01-15T10:10:00Z | 2025-01-17T10:00:00Z | 2870 | 404 | /missing |
This query adds the current timestamp to each record and calculates the elapsed time in minutes since each failed request occurred.
List of related functions#
- ago: Subtracts a given timespan from the current UTC clock time.
- datetime_add: Adds a specified amount to a datetime value.
- datetime_diff: Calculates the difference between two datetime values.
- startofday: Returns the start of the day for a datetime value.
- endofday: Returns the end of the day for a datetime value.
Other query languages#
Splunk SPL users
In Splunk SPL, now() returns the current time as a Unix timestamp. In APL, now() returns a datetime value in UTC and supports an optional timespan offset to shift the returned time forward or backward.
Splunk example
... | eval current_time=now()APL equivalent
... | extend current_time = now()ANSI SQL users
In ANSI SQL, you use CURRENT_TIMESTAMP or NOW() to retrieve the current date and time. In APL, now() behaves similarly but also accepts an optional timespan offset to shift the returned time.
SQL example
SELECT CURRENT_TIMESTAMP AS current_time;APL equivalent
['dataset']
| extend current_time = now()