<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time part is discarding in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Time-part-is-discarding/m-p/509522#M142402</link>
    <description>&lt;P&gt;try &lt;STRONG&gt;kv&amp;nbsp;&lt;/STRONG&gt;before &lt;STRONG&gt;stats&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jul 2020 13:39:55 GMT</pubDate>
    <dc:creator>to4kawa</dc:creator>
    <dc:date>2020-07-16T13:39:55Z</dc:date>
    <item>
      <title>Time part is discarding</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Time-part-is-discarding/m-p/509497#M142389</link>
      <description>&lt;P&gt;I have a timestamp variable&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;EmailSendAt=&lt;SPAN class="t"&gt;&lt;SPAN class="t h"&gt;2020&lt;/SPAN&gt;-07-15&lt;/SPAN&gt; &lt;SPAN class="t"&gt;05:52:13.186&lt;/SPAN&gt;&amp;nbsp;,&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Whenever I am using&lt;BR /&gt;&lt;STRONG&gt;stats value(EmailSendAt) as time..&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;It shows me only Date part.. Time part is discarding. (I used table also but no change happen)&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 11:16:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Time-part-is-discarding/m-p/509497#M142389</guid>
      <dc:creator>sheshanath</dc:creator>
      <dc:date>2020-07-16T11:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: Time part is discarding</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Time-part-is-discarding/m-p/509499#M142391</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=_internal |head 1| fields _raw _time 
| eval _raw="EmailSendAt=2020-07-15 05:52:13.186 , "
| rename COMMENT as "the logic"
| kv&lt;/LI-CODE&gt;&lt;P&gt;your fields extractions is wrong. try &lt;STRONG&gt;kv&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 11:19:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Time-part-is-discarding/m-p/509499#M142391</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-07-16T11:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: Time part is discarding</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Time-part-is-discarding/m-p/509502#M142393</link>
      <description>&lt;P&gt;&lt;STRONG&gt;EmailSendAt&lt;/STRONG&gt; is a field and whenever I pull this field with by&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;stats values(EmailSendAt) as time&lt;/STRONG&gt; .... it shows only date part.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example suppose&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;EmailSendAt=2020-07-15 05:52:13.186&lt;/PRE&gt;&lt;P&gt;then using&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;stats values(EmailSendAt) as time&amp;nbsp;&lt;/STRONG&gt; only shows me date part. Please help&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 11:51:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Time-part-is-discarding/m-p/509502#M142393</guid>
      <dc:creator>sheshanath</dc:creator>
      <dc:date>2020-07-16T11:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Time part is discarding</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Time-part-is-discarding/m-p/509522#M142402</link>
      <description>&lt;P&gt;try &lt;STRONG&gt;kv&amp;nbsp;&lt;/STRONG&gt;before &lt;STRONG&gt;stats&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 13:39:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Time-part-is-discarding/m-p/509522#M142402</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-07-16T13:39:55Z</dc:date>
    </item>
  </channel>
</rss>

