<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to use regex to extract date? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-extract-date/m-p/431204#M123258</link>
    <description>&lt;P&gt;Hello experts , I need some help in extracting date time from the attribute "SrcDtm" in below sample data.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;GI SrcDtm="2019-04-18T18:23:47Z" SrcTmOff="-07:00" SrcAppCd="ABC" SrcCtryCd="IN" SrcFcId="ABCABC" SrcSrvaCd="ABC" SrcFcCd="ABC" CorrId="469429d1-00cd-49a3-906f-fce27fdb4d0c" /&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 25 Apr 2019 11:28:13 GMT</pubDate>
    <dc:creator>kirangurram</dc:creator>
    <dc:date>2019-04-25T11:28:13Z</dc:date>
    <item>
      <title>How to use regex to extract date?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-extract-date/m-p/431204#M123258</link>
      <description>&lt;P&gt;Hello experts , I need some help in extracting date time from the attribute "SrcDtm" in below sample data.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;GI SrcDtm="2019-04-18T18:23:47Z" SrcTmOff="-07:00" SrcAppCd="ABC" SrcCtryCd="IN" SrcFcId="ABCABC" SrcSrvaCd="ABC" SrcFcCd="ABC" CorrId="469429d1-00cd-49a3-906f-fce27fdb4d0c" /&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 25 Apr 2019 11:28:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-extract-date/m-p/431204#M123258</guid>
      <dc:creator>kirangurram</dc:creator>
      <dc:date>2019-04-25T11:28:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to use regex to extract date?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-extract-date/m-p/431205#M123259</link>
      <description>&lt;P&gt;Do you already have those key value pairs extracted as fields? If so, you don't need a rex, just a conversion to timestamp:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eval DateTime = strptime(SrcDtm,"%Y-%m-%dT%H:%M:%SZ")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you have not extracted key value pairs yet, rex would be one way to do that:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex "SrcDtm=\"(?&amp;lt;SrcDtm&amp;gt;[^\"]+)\""
| eval DateTime = strptime(SrcDtm,"%Y-%m-%dT%H:%M:%SZ")
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 25 Apr 2019 11:45:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-extract-date/m-p/431205#M123259</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-04-25T11:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to use regex to extract date?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-extract-date/m-p/431206#M123260</link>
      <description>&lt;P&gt;Like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex "SrcDtm=\"(?&amp;lt;SrcDtm&amp;gt;[^\"]+)"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 26 Apr 2019 04:45:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-extract-date/m-p/431206#M123260</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-04-26T04:45:48Z</dc:date>
    </item>
  </channel>
</rss>

