<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I change the date format of search results? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129434#M35201</link>
    <description>&lt;P&gt;Hi Pablo and thanks for your response.&lt;/P&gt;

&lt;P&gt;Splunk isn't having any trouble recognizing time stamps.  It reads them fine and displays the correct dates in the search results.  The problem is that it displays the dates as mm-dd-yyyy instead of yyyy-mm-dd&lt;/P&gt;</description>
    <pubDate>Fri, 06 Feb 2015 18:27:54 GMT</pubDate>
    <dc:creator>cmartell</dc:creator>
    <dc:date>2015-02-06T18:27:54Z</dc:date>
    <item>
      <title>How can I change the date format of search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129431#M35198</link>
      <description>&lt;P&gt;All of my devices send logs to Splunk with date format set at yyyy-mm-dd, as they should, and Splunk reads them fine and displays the correct dates in the search results but in the wrong format.  The dates are displayed in the default US format of mm-dd-yyyy.  How can I fix this so search results show yyyy-mm-dd?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 17:38:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129431#M35198</guid>
      <dc:creator>cmartell</dc:creator>
      <dc:date>2015-02-06T17:38:27Z</dc:date>
    </item>
    <item>
      <title>Re: How can I change the date format of search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129432#M35199</link>
      <description>&lt;P&gt;Hi @cmartell&lt;/P&gt;

&lt;P&gt;Have you checked out the documentation on configuring proper timestamp recognition at index-time?&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Data/HowSplunkextractstimestamps"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/Data/HowSplunkextractstimestamps&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Data/Configuretimestamprecognition"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/Data/Configuretimestamprecognition&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 18:05:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129432#M35199</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2015-02-06T18:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: How can I change the date format of search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129433#M35200</link>
      <description>&lt;P&gt;Otherwise, you can also do this at search time using &lt;CODE&gt;eval&lt;/CODE&gt; and its function &lt;CODE&gt;strptime&lt;/CODE&gt;, but I'm not sure you'd want to do that every time you run a search.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/SearchReference/CommonEvalFunctions"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/SearchReference/CommonEvalFunctions&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 18:08:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129433#M35200</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2015-02-06T18:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: How can I change the date format of search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129434#M35201</link>
      <description>&lt;P&gt;Hi Pablo and thanks for your response.&lt;/P&gt;

&lt;P&gt;Splunk isn't having any trouble recognizing time stamps.  It reads them fine and displays the correct dates in the search results.  The problem is that it displays the dates as mm-dd-yyyy instead of yyyy-mm-dd&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 18:27:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129434#M35201</guid>
      <dc:creator>cmartell</dc:creator>
      <dc:date>2015-02-06T18:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: How can I change the date format of search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129435#M35202</link>
      <description>&lt;P&gt;Small correction is that the dates are displaying as mm-dd-yy not mm-dd-yyyy&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 18:41:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129435#M35202</guid>
      <dc:creator>cmartell</dc:creator>
      <dc:date>2015-02-06T18:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: How can I change the date format of search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129436#M35203</link>
      <description>&lt;P&gt;are the dates appearing in the raw event as mm-dd-yy or just the table in your search results? This section of the documentation might give you some hints on where to look where the issue might be&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Data/Configuretimestamprecognition#Configure_how_timestamps_appear_in_search_results"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/Data/Configuretimestamprecognition#Configure_how_timestamps_appear_in_search_results&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 18:58:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129436#M35203</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2015-02-06T18:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: How can I change the date format of search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129437#M35204</link>
      <description>&lt;P&gt;In the Time column I am seeing mm-dd-yy and would like to see yyyy-mm-dd.  In the Event column I see mmm dd which is fine.&lt;/P&gt;

&lt;P&gt;I have created a props.conf file in the local folder with this text and it didn't help:&lt;BR /&gt;
[splunkd]&lt;BR /&gt;
TIME_FORMAT = %Y-%m-%d %H:%M:%S&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 19:16:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129437#M35204</guid>
      <dc:creator>cmartell</dc:creator>
      <dc:date>2015-02-06T19:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: How can I change the date format of search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129438#M35205</link>
      <description>&lt;P&gt;Any successes ?&lt;/P&gt;

&lt;P&gt;I also would like have natural (yyyy-mm-dd) date in search results. &lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 13:20:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129438#M35205</guid>
      <dc:creator>jaqb</dc:creator>
      <dc:date>2016-04-07T13:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: How can I change the date format of search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129439#M35206</link>
      <description>&lt;P&gt;No success yet.  This is something Splunk needs to do.  It is the International Standard Date Notation after all.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 14:59:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129439#M35206</guid>
      <dc:creator>cmartell</dc:creator>
      <dc:date>2016-04-07T14:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: How can I change the date format of search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129440#M35207</link>
      <description>&lt;P&gt;Yes please! &lt;BR /&gt;
I can not think of a single good reason why the date presentation format used by the GUI is not a user preference in the GUI.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 08:34:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129440#M35207</guid>
      <dc:creator>jolous</dc:creator>
      <dc:date>2019-03-01T08:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: How can I change the date format of search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129441#M35208</link>
      <description>&lt;P&gt;You need to force splunk to use a locale that has the date format you want.&lt;BR /&gt;
In your case probably en_GB.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Quickfix:&lt;/STRONG&gt; You can override the locale in the url - e.g. &lt;A href="https://splunk/en-GB/app/search/" target="_blank"&gt;https://splunk/en-GB/app/search/&lt;/A&gt;...&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Better fix:&lt;/STRONG&gt; The default locale is specified by the browser - e.g. in prioritised order in chrome://settings/languages.&lt;BR /&gt;
Your problem is probably that your actual preferred language is not supported by splunk, and the first one that in the list that splunk recognises is american english. &lt;BR /&gt;
Add UK english and place it higher than american english and you should be OK.&lt;BR /&gt;
Just make sure you remove any hardwired "en-US/" override from your URL.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Proper fix:&lt;/STRONG&gt; I cannot think of a single reason why date presentation format should not be made a simple user preference, independently of available translation languages and having to know the obscure techicalities of which locale splunk will actually end up using.&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;The locales supported by splunk are de_DE, en_GB, en_US, fr_FR, it_IT, ja_JP, ko_KR, zh_CN, and zh_TW.&lt;BR /&gt;
Source: &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/Userlanguageandlocale" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/Userlanguageandlocale&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:31:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-change-the-date-format-of-search-results/m-p/129441#M35208</guid>
      <dc:creator>jolous</dc:creator>
      <dc:date>2020-09-29T23:31:55Z</dc:date>
    </item>
  </channel>
</rss>

