<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time format conversion from UTC to SGT time in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Time-format-conversion-from-UTC-to-SGT-time/m-p/665802#M228442</link>
    <description>&lt;P&gt;Sorry,&lt;/P&gt;&lt;P&gt;but SGT+8 corresponds to UTC.&lt;/P&gt;&lt;P&gt;If you want to chenge the time format from the displayed to&amp;nbsp;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;"%Y-%m-%d %H:%M:%S"&lt;/STRONG&gt; you should use eval with the time functions:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval Time=strftime(_time,"%Y-%m-%d %H:%M:%S")&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 23 Oct 2023 06:05:58 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-10-23T06:05:58Z</dc:date>
    <item>
      <title>Time format conversion from UTC to SGT time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Time-format-conversion-from-UTC-to-SGT-time/m-p/665800#M228441</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hi Team,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I'm currently receiving AWS CloudWatch logs in Splunk using the add-on. I'm developing a use case and need to utilize the "event Time" field from the logs. I require assistance in converting the event Time from UTC to SGT.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Sample event Time&amp;nbsp;is in UTC +0&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="181.547px" height="47px"&gt;2023-06-30T17:17:52Z&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="181.547px" height="47px"&gt;2023-06-30T21:29:53Z&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="181.547px" height="47px"&gt;2023-06-30T22:32:53Z&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="181.547px" height="47px"&gt;2023-07-01T00:38:53Z&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="181.547px" height="47px"&gt;2023-07-01T04:50:52Z&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="181.547px" height="47px"&gt;2023-07-01T05:53:55Z&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="181.547px" height="47px"&gt;2023-07-01T06:56:54Z&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="181.547px" height="47px"&gt;2023-07-01T07:59:52Z&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="181.547px" height="47px"&gt;2023-07-01T09:02:56Z&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="181.547px" height="47px"&gt;2023-07-01T10:05:54Z&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="181.547px" height="47px"&gt;2023-07-01T11:08:53Z&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="181.547px" height="47px"&gt;2023-07-01T12:11:53Z&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;End result:&amp;nbsp;&amp;nbsp;UTC + 0 to SGT + 8 time.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Expected output format&amp;nbsp;is "%Y-%m-%d %H:%M:%S"&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 05:45:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Time-format-conversion-from-UTC-to-SGT-time/m-p/665800#M228441</guid>
      <dc:creator>NitishUa</dc:creator>
      <dc:date>2023-10-23T05:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: Time format conversion from UTC to SGT time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Time-format-conversion-from-UTC-to-SGT-time/m-p/665802#M228442</link>
      <description>&lt;P&gt;Sorry,&lt;/P&gt;&lt;P&gt;but SGT+8 corresponds to UTC.&lt;/P&gt;&lt;P&gt;If you want to chenge the time format from the displayed to&amp;nbsp;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;"%Y-%m-%d %H:%M:%S"&lt;/STRONG&gt; you should use eval with the time functions:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval Time=strftime(_time,"%Y-%m-%d %H:%M:%S")&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 06:05:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Time-format-conversion-from-UTC-to-SGT-time/m-p/665802#M228442</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-23T06:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Time format conversion from UTC to SGT time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Time-format-conversion-from-UTC-to-SGT-time/m-p/665806#M228446</link>
      <description>&lt;P&gt;Will this change the timezone in the output to SGT?&amp;nbsp;&lt;/P&gt;&lt;P&gt;We want the output to be shifted to SGT and &lt;STRONG&gt;then &lt;/STRONG&gt;formatted to&amp;nbsp;&lt;STRONG&gt;"%Y-%m-%d %H:%M:%S"&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 06:29:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Time-format-conversion-from-UTC-to-SGT-time/m-p/665806#M228446</guid>
      <dc:creator>NitishUa</dc:creator>
      <dc:date>2023-10-23T06:29:06Z</dc:date>
    </item>
  </channel>
</rss>

