Overview

now

You can use now to calculate relative times, filter events by recency, and compute the age of records in your dataset.

Use it when you want to:

  • Filter events to a recent time window.
  • Calculate how long ago an event occurred.
  • Add the current timestamp to query output for audit or comparison purposes.

Usage#

Syntax#

now([offset])

Parameters#

Name Type Description
offset timespan Optional: A timespan added to the current UTC clock time. Default is 0.

Returns#

The current UTC clock time as a datetime. All references to now() within a single statement return the same value.

Use case examples#

Calculate the age of each request in hours to understand how recent events are.

Query

['sample-http-logs']
| extend age_hours = datetime_diff('hour', now(), _time)
| project _time, age_hours, method, status
| take 10

Run in Playground

Output

_time age_hours method status
2025-01-15T10:00:00Z 48 GET 200
2025-01-15T10:05:00Z 47 POST 201
2025-01-15T10:10:00Z 47 GET 500

This query calculates how many hours ago each HTTP request occurred by comparing the event time to the current time.

Find traces from the last 5 minutes to monitor recent activity by service.

Query

['otel-demo-traces']
| where _time > now(-5m)
| summarize trace_count = count() by ['service.name']

Run in Playground

Output

service.name trace_count
frontend 120
cart 85
checkout 42

This query filters traces to those generated in the last 5 minutes and counts them by service name.

Show the current time alongside each failed request to calculate how many minutes have passed since the event.

Query

['sample-http-logs']
| where toint(status) >= 400
| extend current_time = now()
| extend time_since = datetime_diff('minute', current_time, _time)
| project _time, current_time, time_since, status, uri
| take 10

Run in Playground

Output

_time current_time time_since status uri
2025-01-15T10:00:00Z 2025-01-17T10:00:00Z 2880 403 /admin
2025-01-15T10:05:00Z 2025-01-17T10:00:00Z 2875 500 /api/users
2025-01-15T10:10:00Z 2025-01-17T10:00:00Z 2870 404 /missing

This query adds the current timestamp to each record and calculates the elapsed time in minutes since each failed request occurred.

  • ago: Subtracts a given timespan from the current UTC clock time.
  • datetime_add: Adds a specified amount to a datetime value.
  • datetime_diff: Calculates the difference between two datetime values.
  • startofday: Returns the start of the day for a datetime value.
  • endofday: Returns the end of the day for a datetime value.

Other query languages#

Splunk SPL users

In Splunk SPL, now() returns the current time as a Unix timestamp. In APL, now() returns a datetime value in UTC and supports an optional timespan offset to shift the returned time forward or backward.

Splunk example

... | eval current_time=now()

APL equivalent

... | extend current_time = now()
ANSI SQL users

In ANSI SQL, you use CURRENT_TIMESTAMP or NOW() to retrieve the current date and time. In APL, now() behaves similarly but also accepts an optional timespan offset to shift the returned time.

SQL example

SELECT CURRENT_TIMESTAMP AS current_time;

APL equivalent

['dataset']
| extend current_time = now()

Updated

Was this page helpful?