<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strftime/Strptime not including leading zero in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Strftime-Strptime-not-including-leading-zero/m-p/391263#M113941</link>
    <description>&lt;P&gt;That did it, thank you!&lt;/P&gt;</description>
    <pubDate>Thu, 04 Apr 2019 19:45:08 GMT</pubDate>
    <dc:creator>mistydennis</dc:creator>
    <dc:date>2019-04-04T19:45:08Z</dc:date>
    <item>
      <title>Strftime/Strptime not including leading zero</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Strftime-Strptime-not-including-leading-zero/m-p/391260#M113938</link>
      <description>&lt;P&gt;DateField before eval: &lt;STRONG&gt;20190402000000&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I'm trying to apply strftime/strptime so the DateField will show as &lt;STRONG&gt;2019-04-02&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;My eval: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eval DateField=strftime(strptime('DateField',"%Y%m%d"), "%F") 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This eval produces &lt;STRONG&gt;2019-04-20&lt;/STRONG&gt; instead of &lt;STRONG&gt;2019-04-02&lt;/STRONG&gt;. I thought %d included a leading zero, but it's not showing in my date. Where did I go wrong?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 19:34:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Strftime-Strptime-not-including-leading-zero/m-p/391260#M113938</guid>
      <dc:creator>mistydennis</dc:creator>
      <dc:date>2019-04-04T19:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Strftime/Strptime not including leading zero</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Strftime-Strptime-not-including-leading-zero/m-p/391261#M113939</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eval DateField=strftime(strptime('DateField',"%Y%m%d%H%M%S"), "%Y-%m-%d")
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 04 Apr 2019 19:40:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Strftime-Strptime-not-including-leading-zero/m-p/391261#M113939</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2019-04-04T19:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Strftime/Strptime not including leading zero</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Strftime-Strptime-not-including-leading-zero/m-p/391262#M113940</link>
      <description>&lt;P&gt;I believe additional zeros in your timestamp are causing issue. Ideally, your strptime time format should include all characters appearing in your DateField, that way every character is properly processes. Give this a try (runanywhere sample, look for time format in DateField2)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| gentimes start=-1 | eval DateField="20190402000000" | table DateField  | eval DateField1=strftime(strptime('DateField',"%Y%m%d"), "%F")| eval DateField2=strftime(strptime('DateField',"%Y%m%d000000"), "%F")
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 04 Apr 2019 19:42:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Strftime-Strptime-not-including-leading-zero/m-p/391262#M113940</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-04-04T19:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Strftime/Strptime not including leading zero</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Strftime-Strptime-not-including-leading-zero/m-p/391263#M113941</link>
      <description>&lt;P&gt;That did it, thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 19:45:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Strftime-Strptime-not-including-leading-zero/m-p/391263#M113941</guid>
      <dc:creator>mistydennis</dc:creator>
      <dc:date>2019-04-04T19:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Strftime/Strptime not including leading zero</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Strftime-Strptime-not-including-leading-zero/m-p/391264#M113942</link>
      <description>&lt;P&gt;This also worked. Thanks so much, @somesoni2 &lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 19:50:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Strftime-Strptime-not-including-leading-zero/m-p/391264#M113942</guid>
      <dc:creator>mistydennis</dc:creator>
      <dc:date>2019-04-04T19:50:18Z</dc:date>
    </item>
  </channel>
</rss>

