<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Every timespan of transaction need time format in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564620#M196684</link>
    <description>&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have alert transaction at "ACK" and at "Resolved", i have created table for each value, but unable to edit time format of each. Please help. Please find attached image for reference.&lt;/P&gt;&lt;P&gt;Current Output-&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;857415&lt;/TD&gt;&lt;TD&gt;piyush.moorjani piyush.moorjani&lt;/TD&gt;&lt;TD&gt;2021-08-25T01:57:26Z 2021-08-25T01:58:47Z&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="multivalue-subcell"&gt;ACKED&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;RESOLVED&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;need time format of third col.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Aug 2021 02:26:40 GMT</pubDate>
    <dc:creator>Manasi25</dc:creator>
    <dc:date>2021-08-25T02:26:40Z</dc:date>
    <item>
      <title>Every timespan of transaction need time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564620#M196684</link>
      <description>&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have alert transaction at "ACK" and at "Resolved", i have created table for each value, but unable to edit time format of each. Please help. Please find attached image for reference.&lt;/P&gt;&lt;P&gt;Current Output-&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;857415&lt;/TD&gt;&lt;TD&gt;piyush.moorjani piyush.moorjani&lt;/TD&gt;&lt;TD&gt;2021-08-25T01:57:26Z 2021-08-25T01:58:47Z&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="multivalue-subcell"&gt;ACKED&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;RESOLVED&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;need time format of third col.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 02:26:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564620#M196684</guid>
      <dc:creator>Manasi25</dc:creator>
      <dc:date>2021-08-25T02:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: Every timespan of transaction need time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564674#M196697</link>
      <description>&lt;P&gt;Are these multi-value fields? If so, have you tried mvmap to format each value?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 09:56:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564674#M196697</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-25T09:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: Every timespan of transaction need time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564742#M196722</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No i haven't use mvmap for this.&lt;/P&gt;&lt;P&gt;These are multi- value fields from same field called&amp;nbsp;transitions{}.at&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;858681&lt;/TD&gt;&lt;TD&gt;mike.dowling&lt;BR /&gt;mike.dowling&lt;/TD&gt;&lt;TD&gt;2021-08-25T14:44:00Z&lt;BR /&gt;2021-08-25T14:53:40Z&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="multivalue-subcell"&gt;ACKED&lt;/DIV&gt;&lt;DIV class="multivalue-subcell highlighted"&gt;RESOLVED&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 25 Aug 2021 15:01:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564742#M196722</guid>
      <dc:creator>Manasi25</dc:creator>
      <dc:date>2021-08-25T15:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: Every timespan of transaction need time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564759#M196728</link>
      <description>&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval _raw="858681,mike.dowling|mike.dowling,2021-08-25T14:44:00Z|2021-08-25T14:53:40Z,ACKED|RESOLVED"
| eval _raw=split(_raw,",")
| eval incident=mvindex(_raw,0)
| eval name=split(mvindex(_raw,1),"|")
| eval time=split(mvindex(_raw,2),"|")
| eval status=split(mvindex(_raw,3),"|")
| table incident name time status



| eval time=mvmap(time,strftime(strptime(time,"%Y-%m-%dT%H:%M:%S"),"%d/%m/%Y %H:%M:%S"))&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 25 Aug 2021 16:19:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564759#M196728</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-25T16:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: Every timespan of transaction need time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564779#M196738</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have multiple alerts of incidentNumber, user , ack time and resolved time.&lt;BR /&gt;&amp;nbsp;how can i sort my whole data as having lots of rows?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Manasi25_0-1629913791622.png" style="width: 587px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15742i62AC6DA28111FA4D/image-dimensions/587x176?v=v2" width="587" height="176" role="button" title="Manasi25_0-1629913791622.png" alt="Manasi25_0-1629913791622.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 17:50:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564779#M196738</guid>
      <dc:creator>Manasi25</dc:creator>
      <dc:date>2021-08-25T17:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: Every timespan of transaction need time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564783#M196740</link>
      <description>&lt;P&gt;You should probably extract the transitions array, mvexpand it into separate events, then extract the fields from transitions.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 18:08:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564783#M196740</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-25T18:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Every timespan of transaction need time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564809#M196748</link>
      <description>&lt;P&gt;i did mvexpand for this, i need time format for "TIME" col. PFB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Manasi25_0-1629939368230.png" style="width: 618px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15747i3C92EEA8374F3DDF/image-dimensions/618x252?v=v2" width="618" height="252" role="button" title="Manasi25_0-1629939368230.png" alt="Manasi25_0-1629939368230.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 00:56:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564809#M196748</guid>
      <dc:creator>Manasi25</dc:creator>
      <dc:date>2021-08-26T00:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: Every timespan of transaction need time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564829#M196757</link>
      <description>&lt;P&gt;I have shown you how to reformat multi-value fields, but you also mentioned sort - what are you trying to sort by? Perhaps if you gave an example of the desired output, that might help. By the way, you haven't used mvexpand in the way I suggested, but without know what you are trying to achieve, it is hard to know whether what you have done is correct or not.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 06:22:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564829#M196757</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-26T06:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Every timespan of transaction need time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564869#M196771</link>
      <description>&lt;P&gt;hello&lt;BR /&gt;&lt;BR /&gt;I want to time&amp;nbsp; format of column "TIME", i have formatted it, but resulting "NULL" output as these times are showing from single field called "transition{].at" and unable to do format of two values at a time into table.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;startTime&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string"&gt;2021-08-26T11:02:25Z&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;STRONG&gt;&lt;SPAN class="key-name"&gt;transitions&lt;/SPAN&gt;:&amp;nbsp;[&amp;nbsp;&lt;A href="https://splunk.fnfis.com/en-US/app/spog/search?q=search%20index%3Dvictorops%20%20%20%20incidentNumber%3D860894%20%7C%20dedup%20incidentNumber%20%20%7C%20eval%20startTimeFormatted%3Dstrptime(startTime%2C%22%25Y-%25m-%25dT%25H%3A%25M%3A%25SZ%22)%20-18000%20%20%7C%20eval%20SplunkStartTime%3Dstrftime(startTimeFormatted%2C%22%25m%2F%25d%2F%25y%20%25H%3A%25M%3A%25S%22)%20%7C%20eval%20endTimeFormatted%3Dstrptime(lastAlertTime%2C%22%25Y-%25m-%25dT%25H%3A%25M%3A%25SZ%22)%20-18000%20%7C%20eval%20SplunkEndTime%20%3Dstrftime(endTimeFormatted%2C%20%22%25m%2F%25d%2F%25y%20%25H%3A%25M%3A%25S%22)%20%7C%20eval%20MTTR%20%3D%20tostring(endTimeFormatted-startTimeFormatted%2C%22duration%22)%20%20%20%7C%20makemv%20delim%3D%22%2C%22%20transitions%7B%7D.by%20%7C%20makemv%20delim%3D%22%2C%22%20transitions%7B%7D.at%20%7C%20mvexpand%20transitions%7B%7D.by%20%7C%20mvexpand%20transitions%7B%7D.at%20%20%20%7C%20rename%20transitions%7B%7D.by%20as%20user%2C%20transitions%7B%7D.at%20as%20TIME%20&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-4h%40m&amp;amp;latest=now&amp;amp;display.general.type=events&amp;amp;display.page.search.tab=statistics&amp;amp;display.statistics.format.0=number&amp;amp;display.statistics.format.0.precision=0&amp;amp;display.statistics.format.0.field=MTTR&amp;amp;display.statistics.format.1=color&amp;amp;display.statistics.format.0.useThousandSeparators=&amp;amp;display.statistics.format.1.scale=minMidMax&amp;amp;display.statistics.format.1.colorPalette=minMidMax&amp;amp;display.statistics.format.1.colorPalette.minColor=%23FFFFFF&amp;amp;display.statistics.format.1.colorPalette.maxColor=%2353A051&amp;amp;display.statistics.format.1.field=MTTR&amp;amp;display.statistics.format.2=number&amp;amp;display.statistics.format.2.precision=0&amp;amp;display.statistics.format.2.field=TIME&amp;amp;display.events.fields=%5B%22fisVertical%22%2C%22source%22%2C%22timeendpos%22%2C%22timestamp%22%2C%22timestartpos%22%2C%22startTime%22%2C%22lastAlertTime%22%5D&amp;amp;sid=1629977492.101417_5AA947F6-F95F-4423-B0C5-C48958C36B29#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;{&amp;nbsp;&lt;A href="https://splunk.fnfis.com/en-US/app/spog/search?q=search%20index%3Dvictorops%20%20%20%20incidentNumber%3D860894%20%7C%20dedup%20incidentNumber%20%20%7C%20eval%20startTimeFormatted%3Dstrptime(startTime%2C%22%25Y-%25m-%25dT%25H%3A%25M%3A%25SZ%22)%20-18000%20%20%7C%20eval%20SplunkStartTime%3Dstrftime(startTimeFormatted%2C%22%25m%2F%25d%2F%25y%20%25H%3A%25M%3A%25S%22)%20%7C%20eval%20endTimeFormatted%3Dstrptime(lastAlertTime%2C%22%25Y-%25m-%25dT%25H%3A%25M%3A%25SZ%22)%20-18000%20%7C%20eval%20SplunkEndTime%20%3Dstrftime(endTimeFormatted%2C%20%22%25m%2F%25d%2F%25y%20%25H%3A%25M%3A%25S%22)%20%7C%20eval%20MTTR%20%3D%20tostring(endTimeFormatted-startTimeFormatted%2C%22duration%22)%20%20%20%7C%20makemv%20delim%3D%22%2C%22%20transitions%7B%7D.by%20%7C%20makemv%20delim%3D%22%2C%22%20transitions%7B%7D.at%20%7C%20mvexpand%20transitions%7B%7D.by%20%7C%20mvexpand%20transitions%7B%7D.at%20%20%20%7C%20rename%20transitions%7B%7D.by%20as%20user%2C%20transitions%7B%7D.at%20as%20TIME%20&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-4h%40m&amp;amp;latest=now&amp;amp;display.general.type=events&amp;amp;display.page.search.tab=statistics&amp;amp;display.statistics.format.0=number&amp;amp;display.statistics.format.0.precision=0&amp;amp;display.statistics.format.0.field=MTTR&amp;amp;display.statistics.format.1=color&amp;amp;display.statistics.format.0.useThousandSeparators=&amp;amp;display.statistics.format.1.scale=minMidMax&amp;amp;display.statistics.format.1.colorPalette=minMidMax&amp;amp;display.statistics.format.1.colorPalette.minColor=%23FFFFFF&amp;amp;display.statistics.format.1.colorPalette.maxColor=%2353A051&amp;amp;display.statistics.format.1.field=MTTR&amp;amp;display.statistics.format.2=number&amp;amp;display.statistics.format.2.precision=0&amp;amp;display.statistics.format.2.field=TIME&amp;amp;display.events.fields=%5B%22fisVertical%22%2C%22source%22%2C%22timeendpos%22%2C%22timestamp%22%2C%22timestartpos%22%2C%22startTime%22%2C%22lastAlertTime%22%5D&amp;amp;sid=1629977492.101417_5AA947F6-F95F-4423-B0C5-C48958C36B29#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;at&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;2021-08-26T11:03:06Z&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;by&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;asma.sahbani&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;name&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;ACKED&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;{&amp;nbsp;&lt;A href="https://splunk.fnfis.com/en-US/app/spog/search?q=search%20index%3Dvictorops%20%20%20%20incidentNumber%3D860894%20%7C%20dedup%20incidentNumber%20%20%7C%20eval%20startTimeFormatted%3Dstrptime(startTime%2C%22%25Y-%25m-%25dT%25H%3A%25M%3A%25SZ%22)%20-18000%20%20%7C%20eval%20SplunkStartTime%3Dstrftime(startTimeFormatted%2C%22%25m%2F%25d%2F%25y%20%25H%3A%25M%3A%25S%22)%20%7C%20eval%20endTimeFormatted%3Dstrptime(lastAlertTime%2C%22%25Y-%25m-%25dT%25H%3A%25M%3A%25SZ%22)%20-18000%20%7C%20eval%20SplunkEndTime%20%3Dstrftime(endTimeFormatted%2C%20%22%25m%2F%25d%2F%25y%20%25H%3A%25M%3A%25S%22)%20%7C%20eval%20MTTR%20%3D%20tostring(endTimeFormatted-startTimeFormatted%2C%22duration%22)%20%20%20%7C%20makemv%20delim%3D%22%2C%22%20transitions%7B%7D.by%20%7C%20makemv%20delim%3D%22%2C%22%20transitions%7B%7D.at%20%7C%20mvexpand%20transitions%7B%7D.by%20%7C%20mvexpand%20transitions%7B%7D.at%20%20%20%7C%20rename%20transitions%7B%7D.by%20as%20user%2C%20transitions%7B%7D.at%20as%20TIME%20&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=-4h%40m&amp;amp;latest=now&amp;amp;display.general.type=events&amp;amp;display.page.search.tab=statistics&amp;amp;display.statistics.format.0=number&amp;amp;display.statistics.format.0.precision=0&amp;amp;display.statistics.format.0.field=MTTR&amp;amp;display.statistics.format.1=color&amp;amp;display.statistics.format.0.useThousandSeparators=&amp;amp;display.statistics.format.1.scale=minMidMax&amp;amp;display.statistics.format.1.colorPalette=minMidMax&amp;amp;display.statistics.format.1.colorPalette.minColor=%23FFFFFF&amp;amp;display.statistics.format.1.colorPalette.maxColor=%2353A051&amp;amp;display.statistics.format.1.field=MTTR&amp;amp;display.statistics.format.2=number&amp;amp;display.statistics.format.2.precision=0&amp;amp;display.statistics.format.2.field=TIME&amp;amp;display.events.fields=%5B%22fisVertical%22%2C%22source%22%2C%22timeendpos%22%2C%22timestamp%22%2C%22timestartpos%22%2C%22startTime%22%2C%22lastAlertTime%22%5D&amp;amp;sid=1629977492.101417_5AA947F6-F95F-4423-B0C5-C48958C36B29#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;at&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;2021-08-26T11:12:58Z&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;by&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;asma.sahbani&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;manually&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t boolean"&gt;true&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;name&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;RESOLVED&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 12:03:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/564869#M196771</guid>
      <dc:creator>Manasi25</dc:creator>
      <dc:date>2021-08-26T12:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: Every timespan of transaction need time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/566288#M197358</link>
      <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any update on this?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2021 11:17:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/566288#M197358</guid>
      <dc:creator>Manasi25</dc:creator>
      <dc:date>2021-09-08T11:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: Every timespan of transaction need time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/566289#M197359</link>
      <description>&lt;P&gt;Did you try the mvmap solution I proposed earlier? What were the results?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2021 11:28:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/566289#M197359</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-09-08T11:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: Every timespan of transaction need time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/568264#M198023</link>
      <description>&lt;P&gt;here is result, it worked, but how can we use on my source type/index?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Please help, i m just a beginner.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Manasi25_0-1632409789358.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16140i0776F99D35C69C48/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Manasi25_0-1632409789358.png" alt="Manasi25_0-1632409789358.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;My data is below,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Manasi25_0-1632410051510.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16141i99EC9C6377B8046C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Manasi25_0-1632410051510.png" alt="Manasi25_0-1632410051510.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 15:14:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/568264#M198023</guid>
      <dc:creator>Manasi25</dc:creator>
      <dc:date>2021-09-23T15:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Every timespan of transaction need time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/568276#M198028</link>
      <description>&lt;P&gt;OK you field appears to be called TIME rather than time as in my example, so try&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval TIME=mvmap(TIME,strftime(strptime(TIME,"%Y-%m-%dT%H:%M:%S"),"%d/%m/%Y %H:%M:%S"))&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 23 Sep 2021 15:53:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/568276#M198028</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-09-23T15:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: Every timespan of transaction need time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/568314#M198039</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;It worked, but showing incorrect time of "ACK" alerts and it's skipping "Resolved" time in second row of single "incidentNumber".&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Manasi25_0-1632445812736.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16146i96113C379F345EB4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Manasi25_0-1632445812736.png" alt="Manasi25_0-1632445812736.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2021 01:10:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/568314#M198039</guid>
      <dc:creator>Manasi25</dc:creator>
      <dc:date>2021-09-24T01:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Every timespan of transaction need time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/568327#M198043</link>
      <description>&lt;P&gt;You appear to be making a 5 hour adjustment to times elsewhere in the search so you could do the same here&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval TIME=mvmap(TIME,strftime(strptime(TIME,"%Y-%m-%dT%H:%M:%S")-18000,"%d/%m/%Y %H:%M:%S"))&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 24 Sep 2021 06:11:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/568327#M198043</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-09-24T06:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: Every timespan of transaction need time format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/568699#M198195</link>
      <description>&lt;P&gt;Thank you ! it worked.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 11:12:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-timespan-of-transaction-need-time-format/m-p/568699#M198195</guid>
      <dc:creator>Manasi25</dc:creator>
      <dc:date>2021-09-28T11:12:25Z</dc:date>
    </item>
  </channel>
</rss>

