unixtime_microseconds_todatetime
Use the function whenever you ingest data that stores time as epoch microseconds (for example, JSON logs from NGINX or metrics that follow the StatsD line protocol). Converting to datetime lets you bin, filter, and visualize events with the rest of your time-series data.
Usage#
Syntax#
unixtime_microseconds_todatetime(microseconds)Parameters#
| Name | Type | Description |
|---|---|---|
microseconds |
int or long |
Whole microseconds since the Unix epoch. Fractional input is truncated. |
Returns#
A datetime value that represents the given epoch microseconds at UTC precision (1 microsecond).
Use case example#
The HTTP access logs keep the timestamp as epoch microseconds and you want to convert the values to datetime.
Query
['sample-http-logs']
| extend epoch_microseconds = toint(datetime_diff('Microsecond', _time, datetime(1970-01-01)))
| extend datetime_standard = unixtime_microseconds_todatetime(epoch_microseconds)
| project _time, epoch_microseconds, datetime_standardOutput
| _time | epoch_microseconds | datetime_standard |
|---|---|---|
| May 15, 12:09:22 | 1,747,303,762 | 2025-05-15T10:09:22Z |
This query converts the timestamp to epoch microseconds and then back to datetime for demonstration purposes.
List of related functions#
- unixtime_milliseconds_todatetime: Converts a Unix timestamp expressed in whole milliseconds to an APL
datetimevalue. - unixtime_nanoseconds_todatetime: Converts a Unix timestamp expressed in whole nanoseconds to an APL
datetimevalue. - unixtime_seconds_todatetime: Converts a Unix timestamp expressed in whole seconds to an APL
datetimevalue.
Other query languages#
Splunk SPL users
In Splunk, you often convert epoch values with eval ts=strftime(_time,"%Y-%m-%dT%H:%M:%S.%6N"). In APL, the conversion happens with a scalar function, so you can use it inline wherever a datetime literal is accepted.
Splunk example
| eval eventTime=strftime( micro_ts/1000000 , "%Y-%m-%dT%H:%M:%S.%6N")APL equivalent
| extend eventTime = unixtime_microseconds_todatetime(micro_ts)ANSI SQL users
Standard SQL engines rarely expose microsecond-epoch helpers. You usually cast or divide by 1,000,000 and add an interval. APL gives you a dedicated scalar function that returns a native datetime, which then supports the full date-time syntax.
SQL example
SELECT TIMESTAMP '1970-01-01 00:00:00' + micro_ts / 1000000 * INTERVAL '1 second' FROM events;APL equivalent
['events']
| extend eventTime = unixtime_microseconds_todatetime(micro_ts)