<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Search Query which should match date format shown in logs. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555718#M157761</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235308"&gt;@sunket6006&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See if following works, file_billing field having the date format that you require extracted from file ends with .csv.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=securecode host IN (cjb4stl181) sourcetype=securecode:billing:txn_gft "Execution failure in Transferring Transaction Billing File ::"
| rex field=file "(?&amp;lt;file_billing&amp;gt;\d+)\.csv" 
| table file file_billing&lt;/LI-CODE&gt;&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if if helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jun 2021 05:30:34 GMT</pubDate>
    <dc:creator>venkatasri</dc:creator>
    <dc:date>2021-06-15T05:30:34Z</dc:date>
    <item>
      <title>Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555689#M157754</link>
      <description>&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t"&gt;From&lt;/SPAN&gt; &lt;SPAN class="t"&gt;file&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=/apps_data_01/scds2/billing/processed/ICD_TXN2_210613.csv&lt;/SPAN&gt; &lt;SPAN class="t"&gt;To&lt;/SPAN&gt; &lt;SPAN class="t"&gt;node&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=snode=MCCDPVPN&lt;/SPAN&gt; &lt;SPAN class="t"&gt;To&lt;/SPAN&gt; &lt;SPAN class="t"&gt;user&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt; &lt;SPAN class="t"&gt;To&lt;/SPAN&gt; &lt;SPAN class="t"&gt;file&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=DTF.AR.R8D1.C.E0084977.D210614.T120015.C003&lt;/SPAN&gt; &lt;SPAN class="t"&gt;To&lt;/SPAN&gt; &lt;SPAN class="t"&gt;permiss&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt; &lt;SPAN class="t"&gt;To&lt;/SPAN&gt; &lt;SPAN class="t"&gt;disp&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=rpl&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Xfer&lt;/SPAN&gt; &lt;SPAN class="t"&gt;type&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=text&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Xfer&lt;/SPAN&gt; &lt;SPAN class="t"&gt;late&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt; &lt;SPAN class="t"&gt;DCB&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=RECFM=VB&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;LRECL=27994&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;BLKSIZE=27998&lt;/SPAN&gt; &lt;SPAN class="t"&gt;SPACE&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sysopts&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=:datatype=text:strip.blanks=no:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;disp&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=disp=&lt;/SPAN&gt;(&lt;SPAN class="t"&gt;rpl&lt;/SPAN&gt;) &lt;SPAN class="t"&gt;dcbline&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=DCB=&lt;/SPAN&gt;(&lt;SPAN class="t"&gt;RECFM=VB&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;LRECL=27994&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;BLKSIZE=27998&lt;/SPAN&gt;) &lt;SPAN class="t"&gt;UC7&lt;/SPAN&gt; &lt;SPAN class="t"&gt;posting&lt;/SPAN&gt; &lt;SPAN class="t"&gt;info&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=run&lt;/SPAN&gt; &lt;SPAN class="t"&gt;task&lt;/SPAN&gt; &lt;SPAN class="t"&gt;snode&lt;/SPAN&gt; (&lt;SPAN class="t"&gt;pgm=U7SVC&lt;/SPAN&gt;) &lt;SPAN class="t"&gt;sysopts=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;CL46&lt;/SPAN&gt;'&lt;SPAN class="t"&gt;D=DTF.AR.R8D1.C.E0084977.D210614.T120015.C003&lt;/SPAN&gt;'" &lt;SPAN class="t"&gt;volume&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ser&lt;/SPAN&gt; &lt;SPAN class="t"&gt;info&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=/&lt;/SPAN&gt;* &lt;SPAN class="t"&gt;mainframe&lt;/SPAN&gt; &lt;SPAN class="t"&gt;volume&lt;/SPAN&gt; &lt;SPAN class="t"&gt;info&lt;/SPAN&gt; &lt;SPAN class="t"&gt;not&lt;/SPAN&gt; &lt;SPAN class="t"&gt;needed&lt;/SPAN&gt; *&lt;SPAN class="t"&gt;/&lt;/SPAN&gt; &lt;SPAN class="t"&gt;unit&lt;/SPAN&gt; &lt;SPAN class="t"&gt;info&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=UNIT=PROD&lt;/SPAN&gt; &lt;SPAN class="t"&gt;status&lt;/SPAN&gt; &lt;SPAN class="t"&gt;file&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=/sys_apps_01/cdunix/ndm/work/cjb4stl181/&lt;/SPAN&gt; &lt;SPAN class="t"&gt;process&lt;/SPAN&gt; &lt;SPAN class="t"&gt;name&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=cd11547&lt;/SPAN&gt; &lt;SPAN class="t"&gt;return&lt;/SPAN&gt; &lt;SPAN class="t"&gt;code&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=4&lt;/SPAN&gt; &lt;SPAN class="t"&gt;date/time&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=Mon&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Jun&lt;/SPAN&gt; &lt;SPAN class="t"&gt;14&lt;/SPAN&gt; &lt;SPAN class="t"&gt;12:00:49&lt;/SPAN&gt; &lt;SPAN class="t"&gt;CDT&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=====================================================================================&lt;/SPAN&gt; &lt;SPAN class="t"&gt;21/06/14&lt;/SPAN&gt; &lt;SPAN class="t"&gt;12:00:49&lt;/SPAN&gt; [&lt;SPAN class="t"&gt;ERROR&lt;/SPAN&gt;] &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;Execution&lt;/SPAN&gt; &lt;SPAN class="t"&gt;failure&lt;/SPAN&gt; &lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Transferring&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Transaction&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Billing&lt;/SPAN&gt; &lt;SPAN class="t"&gt;File&lt;/SPAN&gt; &lt;SPAN class="t"&gt;::&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;210613&lt;/SPAN&gt;&lt;/DIV&gt;&lt;A href="https://dtl.splunk.mastercard.int/en-US/app/mc_ea_all_search/search?earliest=-30d%40d&amp;amp;latest=now&amp;amp;q=search%20index%3Dsecurecode%20host%20IN%20(cjb4stl181)%20sourcetype%3Dsecurecode%3Abilling%3Atxn_gft%20%22Execution%20failure%20in%20Transferring%20Transaction%20Billing%20File%20%3A%3A%22&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;display.page.search.tab=events&amp;amp;sid=1623698827.106550#" target="_blank" rel="noopener"&gt;Collapse&lt;/A&gt;&lt;/DIV&gt;&lt;DIV class="shared-eventsviewer-list-body-row-selectedfields"&gt;&lt;UL class="condensed-selected-fields"&gt;&lt;LI&gt;&lt;SPAN class="field"&gt;host =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value a"&gt;&lt;A title="cjb4stl181" href="https://dtl.splunk.mastercard.int/en-US/app/mc_ea_all_search/search?earliest=-30d%40d&amp;amp;latest=now&amp;amp;q=search%20index%3Dsecurecode%20host%20IN%20(cjb4stl181)%20sourcetype%3Dsecurecode%3Abilling%3Atxn_gft%20%22Execution%20failure%20in%20Transferring%20Transaction%20Billing%20File%20%3A%3A%22&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;display.page.search.tab=events&amp;amp;sid=1623698827.106550#" target="_blank" rel="noopener"&gt;cjb4stl181&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="field"&gt;source =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value"&gt;&lt;A title="/apps_data_01/scds2/billing/processed/txn_billing_gft.log" href="https://dtl.splunk.mastercard.int/en-US/app/mc_ea_all_search/search?earliest=-30d%40d&amp;amp;latest=now&amp;amp;q=search%20index%3Dsecurecode%20host%20IN%20(cjb4stl181)%20sourcetype%3Dsecurecode%3Abilling%3Atxn_gft%20%22Execution%20failure%20in%20Transferring%20Transaction%20Billing%20File%20%3A%3A%22&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;display.page.search.tab=events&amp;amp;sid=1623698827.106550#" target="_blank" rel="noopener"&gt;/apps_data_01/scds2/billing/processed/txn_billing_gft.log&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="field"&gt;sourcetype =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value a"&gt;&lt;A title="securecode:billing:txn_gft" href="https://dtl.splunk.mastercard.int/en-US/app/mc_ea_all_search/search?earliest=-30d%40d&amp;amp;latest=now&amp;amp;q=search%20index%3Dsecurecode%20host%20IN%20(cjb4stl181)%20sourcetype%3Dsecurecode%3Abilling%3Atxn_gft%20%22Execution%20failure%20in%20Transferring%20Transaction%20Billing%20File%20%3A%3A%22&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;display.page.search.tab=events&amp;amp;sid=1623698827.106550#" target="_blank" rel="noopener"&gt;securecode:billing:txn_gft&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="field-value a"&gt;Above are the logs shown in splunk. Splunk query used for it is below. I need a query which should match the date -&lt;SPAN class="t"&gt;210613. Please help me.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="field-value a"&gt;index=securecode host IN (cjb4stl181) sourcetype=securecode:billing:txn_gft "Execution failure in Transferring Transaction Billing File ::"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 14 Jun 2021 19:31:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555689#M157754</guid>
      <dc:creator>sunket6006</dc:creator>
      <dc:date>2021-06-14T19:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555718#M157761</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235308"&gt;@sunket6006&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See if following works, file_billing field having the date format that you require extracted from file ends with .csv.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=securecode host IN (cjb4stl181) sourcetype=securecode:billing:txn_gft "Execution failure in Transferring Transaction Billing File ::"
| rex field=file "(?&amp;lt;file_billing&amp;gt;\d+)\.csv" 
| table file file_billing&lt;/LI-CODE&gt;&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if if helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 05:30:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555718#M157761</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-15T05:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555787#M157797</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163730"&gt;@venkatasri&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to filter the below line&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;21/06/14&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;12:00:49&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;[&lt;/SPAN&gt;&lt;SPAN class="t"&gt;ERROR&lt;/SPAN&gt;&lt;SPAN&gt;]&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;Execution&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;failure&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;in&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Transferring&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Transaction&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Billing&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;File&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;::&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;210613&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Search query should match only the above statement and filter it. There is only one event occurring everyday with the date of previous day. The query you suggested also showing few other events that I don't want.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;I am also trying the below query&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;index=securecode host IN (cjb4stl181) sourcetype=securecode:billing:txn_gft "*Execution failure in Transferring Transaction Billing File :: " .strftime(relative_time(now(), "-1d@d"), "%y%m%d") . "*"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;which matches to -&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t a"&gt;Execution&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;failure&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Transferring&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Transaction&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Billing&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;File&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;::&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;210613 but that expression is not evaluating. Do you know why&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 14:04:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555787#M157797</guid>
      <dc:creator>sunket6006</dc:creator>
      <dc:date>2021-06-15T14:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555792#M157798</link>
      <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=securecode host IN (cjb4stl181) sourcetype=securecode:billing:txn_gft "*Execution failure in Transferring Transaction Billing File :: " [| eval yesterday=strftime(relative_time(now(), "-1d@d"), "%y%m%d") | return yesterday]&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 15 Jun 2021 14:23:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555792#M157798</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-15T14:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555817#M157811</link>
      <description>&lt;P&gt;That one is also not working. I am able to match the sentence upto&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Execution failure in Transferring Transaction Billing File :: &lt;/LI-CODE&gt;&lt;P&gt;There are previous 10 events with the same statement but got different dates as below. But I want only want one event with the search matching yesterdays event.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 15:40:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555817#M157811</guid>
      <dc:creator>sunket6006</dc:creator>
      <dc:date>2021-06-15T15:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555818#M157812</link>
      <description>&lt;P&gt;That one is also not working. I am able to match the sentence upto&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Execution failure in Transferring Transaction Billing File :: &lt;/PRE&gt;&lt;P&gt;There are previous 10 events with the same statement but got different dates as below. But I want only want one event with the search matching yesterdays event which is 210614.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;Execution&lt;/SPAN&gt; &lt;SPAN class="t"&gt;failure&lt;/SPAN&gt; &lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Transferring&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Transaction&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Billing&lt;/SPAN&gt; &lt;SPAN class="t"&gt;File&lt;/SPAN&gt; &lt;SPAN class="t"&gt;::&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class="t"&gt;210614&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t a"&gt;Execution failure in Transferring Transaction Billing File :: &lt;/SPAN&gt;210613&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t a"&gt;Execution failure in Transferring Transaction Billing File :: &lt;/SPAN&gt;210611&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t a"&gt;Execution failure in Transferring Transaction Billing File :: &lt;/SPAN&gt;210610&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 15:46:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555818#M157812</guid>
      <dc:creator>sunket6006</dc:creator>
      <dc:date>2021-06-15T15:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555822#M157813</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=securecode host IN (cjb4stl181) sourcetype=securecode:billing:txn_gft
| where match(_raw,strftime(relative_time(now(), "-1d@d"), "Execution failure in Transferring Transaction Billing File :: %y%m%d"))&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 15 Jun 2021 16:15:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555822#M157813</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-15T16:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555827#M157816</link>
      <description>&lt;P&gt;I am sorry, not working as expected.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 16:31:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555827#M157816</guid>
      <dc:creator>sunket6006</dc:creator>
      <dc:date>2021-06-15T16:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555831#M157819</link>
      <description>&lt;LI-CODE lang="markup"&gt;| makeresults count=5
| streamstats count as row 
| eval _raw="other stuff before Execution failure in Transferring Transaction Billing File :: 21061".(row-1)." other stuff afterwards"
| fields - _time row
| where match(_raw,strftime(relative_time(now(), "-1d@d"), "Execution failure in Transferring Transaction Billing File :: %y%m%d"))&lt;/LI-CODE&gt;&lt;P&gt;The first 4 lines set up some dummy data (if you just run those, you will see the 5 lines of dummy data). The last line just matches with yesterday's date.&lt;/P&gt;&lt;P&gt;Which part of this does not work for you? Do you get no results, or too many?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 16:49:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555831#M157819</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-15T16:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555832#M157820</link>
      <description>&lt;P class="lia-indent-padding-left-30px"&gt;I get no results.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 16:50:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555832#M157820</guid>
      <dc:creator>sunket6006</dc:creator>
      <dc:date>2021-06-15T16:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555833#M157821</link>
      <description>&lt;P&gt;You could try this (I had added the "Execution failure ..." string to the match in case the date appeared in the message somewhere else but perhaps that was unnecessary)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=securecode host IN (cjb4stl181) sourcetype=securecode:billing:txn_gft
"Execution failure in Transferring Transaction Billing File ::"
| where match(_raw,strftime(relative_time(now(), "-1d@d"), "%y%m%d"))&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 15 Jun 2021 16:56:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555833#M157821</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-15T16:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555834#M157822</link>
      <description>&lt;P&gt;what is _raw here?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 17:03:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555834#M157822</guid>
      <dc:creator>sunket6006</dc:creator>
      <dc:date>2021-06-15T17:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555837#M157824</link>
      <description>&lt;P&gt;_raw is a special field that holds the whole event so the match against _raw is similar (but not identical) to doing a search, but the match will allow you to use a calculated value e.g. the date.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 17:38:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555837#M157824</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-15T17:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555840#M157826</link>
      <description>&lt;P&gt;not working , is it possible for you to see the logs I can show you.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 17:53:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555840#M157826</guid>
      <dc:creator>sunket6006</dc:creator>
      <dc:date>2021-06-15T17:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555843#M157828</link>
      <description>&lt;P&gt;Sure - send me a private message if you don't want to share here&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 18:00:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555843#M157828</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-15T18:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555845#M157829</link>
      <description>&lt;P&gt;Below are the 2 events for example listed I apply search Query -&lt;STRONG&gt;&amp;nbsp;index=securecode host IN (cjb4stl181) sourcetype=securecode:billing:txn_gft "Execution failure in Transferring Transaction Billing File ::"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;But I only want todays event that should match date "&lt;SPAN class="t"&gt;&lt;STRONG&gt;210614&lt;/STRONG&gt;", I have tried your queries none of them working fine. Please help.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 21:21:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555845#M157829</guid>
      <dc:creator>sunket6006</dc:creator>
      <dc:date>2021-06-15T21:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555846#M157830</link>
      <description>&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw="=====================================================================================
From file =/apps_data_01/scds2/billing/processed/ICD_TXN2_210613.csv To node =snode=MCCDPVPN To user = To file =DTF.AR.R8D1.C.E0084977.D210614.T120015.C003 To permiss = To disp =rpl Xfer type =text Xfer late = DCB =RECFM=VB,LRECL=27994,BLKSIZE=27998 SPACE = sysopts =:datatype=text:strip.blanks=no: disp =disp=(rpl) dcbline =DCB=(RECFM=VB,LRECL=27994,BLKSIZE=27998) UC7 posting info =run task snode (pgm=U7SVC) sysopts=\"CL46'D=DTF.AR.R8D1.C.E0084977.D210614.T120015.C003'\" volume ser info =/* mainframe volume info not needed */ unit info =UNIT=PROD status file =/sys_apps_01/cdunix/ndm/work/cjb4stl181/ process name =cd11547 return code =4 date/time =Mon Jun 14 12:00:49 CDT 2021
=====================================================================================
21/06/14 12:00:49 [ERROR] - Execution failure in Transferring Transaction Billing File :: 210613|=====================================================================================
From file =/apps_data_01/scds2/billing/processed/ICD_TXN2_210614.csv To node =snode=MCCDPVPN To user = To file =DTF.AR.R8D1.C.E0084977.D210615.T120010.C003 To permiss = To disp =rpl Xfer type =text Xfer late = DCB =RECFM=VB,LRECL=27994,BLKSIZE=27998 SPACE = sysopts =:datatype=text:strip.blanks=no: disp =disp=(rpl) dcbline =DCB=(RECFM=VB,LRECL=27994,BLKSIZE=27998) UC7 posting info =run task snode (pgm=U7SVC) sysopts=\"CL46'D=DTF.AR.R8D1.C.E0084977.D210615.T120010.C003'\" volume ser info =/* mainframe volume info not needed */ unit info =UNIT=PROD status file =/sys_apps_01/cdunix/ndm/work/cjb4stl181/ process name =cd27950 return code =4 date/time =Tue Jun 15 12:00:44 CDT 2021
=====================================================================================
21/06/15 12:00:44 [ERROR] - Execution failure in Transferring Transaction Billing File :: 210614"
| eval events=split(_raw,"|") 
| mvexpand events
| eval _raw=events
| fields - _time events
| where match(_raw,strftime(relative_time(now(), "-1d@d"), "Execution failure in Transferring Transaction Billing File :: %y%m%d"))&lt;/LI-CODE&gt;&lt;P&gt;This appears to work&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 19:01:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555846#M157830</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-15T19:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555847#M157831</link>
      <description>&lt;P&gt;You should not use the events which I have given, there are 100 of previous events like that&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 19:06:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555847#M157831</guid>
      <dc:creator>sunket6006</dc:creator>
      <dc:date>2021-06-15T19:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Query which should match date format shown in logs.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555848#M157832</link>
      <description>&lt;P&gt;You are not getting my question preoperly, can we talk on the phone?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 19:07:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Query-which-should-match-date-format-shown-in-logs/m-p/555848#M157832</guid>
      <dc:creator>sunket6006</dc:creator>
      <dc:date>2021-06-15T19:07:07Z</dc:date>
    </item>
  </channel>
</rss>

