unixtime_nanoseconds_todatetime

This page explains how to use the unixtime_nanoseconds_todatetime function in APL.

unixtime_nanoseconds_todatetime converts a Unix timestamp that’s expressed in whole nanoseconds since 1970-01-01 00:00:00 UTC to an APL datetime value.

Use the function whenever you ingest data that stores time as epoch nanoseconds (for example, JSON logs from NGINX or metrics that follow the StatsD line protocol). Converting to datetime lets you bin, filter, and visualize events with the rest of your time-series data.

Usage

Syntax

unixtime_nanoseconds_todatetime(nanoseconds)

Parameters

NameTypeDescription
nanosecondsint or longWhole nanoseconds since the Unix epoch. Fractional input is truncated.

Returns

A datetime value that represents the given epoch nanoseconds at UTC precision (1 nanosecond).

Use case example

The HTTP access logs keep the timestamp as epoch nanoseconds and you want to convert the values to datetime.

Query

['sample-http-logs']
| extend epoch_nanoseconds = toint(datetime_diff('Nanosecond', _time, datetime(1970-01-01)))
| extend datetime_standard = unixtime_nanoseconds_todatetime(epoch_nanoseconds)
| project _time, epoch_nanoseconds, datetime_standard

Run in Playground

Output

_timeepoch_nanosecondsdatetime_standard
May 15, 12:09:221,747,303,7622025-05-15T10:09:22Z

This query converts the timestamp to epoch nanoseconds and then back to datetime for demonstration purposes.

Other query languages