<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: _time format in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513570#M144095</link>
    <description>&lt;P&gt;you can use the table command to choose the fields to display&lt;BR /&gt;| table creation_time, modification_time etc.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Aug 2020 13:09:38 GMT</pubDate>
    <dc:creator>stonefr33</dc:creator>
    <dc:date>2020-08-11T13:09:38Z</dc:date>
    <item>
      <title>_time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513543#M144085</link>
      <description>&lt;P&gt;Our data input contains two timestamp fields — creation_time and modification_time — both formatted in line with&amp;nbsp;ISO 8601 (yyyy/mm/dd hh:mm:ss.ms).&lt;/P&gt;&lt;P&gt;Splunk parses&amp;nbsp;modification_time as _time but, in doing so, it applies the system-default timestamp format, in our case the British one (dd/mm/yyyy hh:mm:ss.ms).&lt;/P&gt;&lt;P&gt;Is there any way that we can either:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Change the timestamp format of &lt;STRONG&gt;_time&lt;/STRONG&gt;&amp;nbsp;(not "eval time = _time" etc) so that they match?&lt;BR /&gt;or&lt;/LI&gt;&lt;LI&gt;Hide or replace _time in search results, dashboard table panels, etc so that we can use the original,&amp;nbsp;modification_time field instead?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-08-11 12-03-26 - Search__Splunk_8.0.5_-_Google_Chrome.png" style="width: 432px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10194iADFE41D2DA8F107F/image-size/large?v=v2&amp;amp;px=999" role="button" title="2020-08-11 12-03-26 - Search__Splunk_8.0.5_-_Google_Chrome.png" alt="2020-08-11 12-03-26 - Search__Splunk_8.0.5_-_Google_Chrome.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 11:04:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513543#M144085</guid>
      <dc:creator>benhooper</dc:creator>
      <dc:date>2020-08-11T11:04:07Z</dc:date>
    </item>
    <item>
      <title>Re: _time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513565#M144093</link>
      <description>&lt;P&gt;What happens when you just omit the _time from search result/dashboard panel by just adding&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|fields - _time&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 11 Aug 2020 12:55:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513565#M144093</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-08-11T12:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: _time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513568#M144094</link>
      <description>&lt;P&gt;The column remains but the fields / cells / values are blank:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-08-11 13-58-42 - Search__Splunk_8.0.5_-_Google_Chrome.png" style="width: 672px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10199iB71A43285C5D33BC/image-size/large?v=v2&amp;amp;px=999" role="button" title="2020-08-11 13-58-42 - Search__Splunk_8.0.5_-_Google_Chrome.png" alt="2020-08-11 13-58-42 - Search__Splunk_8.0.5_-_Google_Chrome.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 12:59:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513568#M144094</guid>
      <dc:creator>benhooper</dc:creator>
      <dc:date>2020-08-11T12:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: _time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513570#M144095</link>
      <description>&lt;P&gt;you can use the table command to choose the fields to display&lt;BR /&gt;| table creation_time, modification_time etc.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 13:09:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513570#M144095</guid>
      <dc:creator>stonefr33</dc:creator>
      <dc:date>2020-08-11T13:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: _time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513573#M144097</link>
      <description>&lt;P&gt;That works for a search but not in the dashboard table panels, even when omitting _time from &amp;lt;fields&amp;gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 13:15:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513573#M144097</guid>
      <dc:creator>benhooper</dc:creator>
      <dc:date>2020-08-11T13:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: _time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513577#M144101</link>
      <description>&lt;P&gt;Is your visualisation 'Events' or 'Stats Table'? Should work for Stats table view but if that view doesn't work for you then you could cheat a little.&lt;/P&gt;&lt;P&gt;| eval _time = modification_time&amp;nbsp;&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;You can play with the time formatting with eval strptime (convert to unixtime) and feed that to strftime (format it the way you want) , but it may be more hassle then its worth.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/SearchReference/Commontimeformatvariables" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/SearchReference/Commontimeformatvariables&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 13:36:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513577#M144101</guid>
      <dc:creator>stonefr33</dc:creator>
      <dc:date>2020-08-11T13:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: _time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513579#M144102</link>
      <description>&lt;P&gt;Ah, it's an events table. Sorry, I forgot that there was another.&lt;/P&gt;&lt;P&gt;Unfortunately, "&lt;SPAN&gt;eval _time = modification_time " doesn't make a difference - the format stays the same. I supposed that's to be expected, though, as _time is originally derived from&amp;nbsp;modification_time anyway. It's like _time has a hardcoded regional time format or something.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 13:45:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513579#M144102</guid>
      <dc:creator>benhooper</dc:creator>
      <dc:date>2020-08-11T13:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: _time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513581#M144104</link>
      <description>&lt;P&gt;Does this work for you?&lt;BR /&gt;&lt;BR /&gt;| eval _time=strftime(_time,"%F %H:%M:%S.%3Q")&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 14:03:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513581#M144104</guid>
      <dc:creator>stonefr33</dc:creator>
      <dc:date>2020-08-11T14:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: _time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513582#M144105</link>
      <description>&lt;P&gt;I'm afraid not. The format stays the same.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 14:10:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513582#M144105</guid>
      <dc:creator>benhooper</dc:creator>
      <dc:date>2020-08-11T14:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: _time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513584#M144106</link>
      <description>&lt;P&gt;Sorry but that's all the tricks I know, not sure if there is something on the backend that can override it. Any of these recommendations I have sent have worked in my environment, but I'm not an admin so unsure of the backend wizardry.&lt;/P&gt;&lt;P&gt;Good luck&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 14:29:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513584#M144106</guid>
      <dc:creator>stonefr33</dc:creator>
      <dc:date>2020-08-11T14:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: _time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513585#M144107</link>
      <description>&lt;P&gt;Thanks anyway!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 14:30:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/513585#M144107</guid>
      <dc:creator>benhooper</dc:creator>
      <dc:date>2020-08-11T14:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: _time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/518619#M145919</link>
      <description>&lt;P&gt;I found that it's only the Events Table that has a permanent _time column so I simply used a Statistics Table instead.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 08:28:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/time-format/m-p/518619#M145919</guid>
      <dc:creator>benhooper</dc:creator>
      <dc:date>2020-09-09T08:28:05Z</dc:date>
    </item>
  </channel>
</rss>

