<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to combine two separate date and time fields into one timestamp field? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-combine-two-separate-date-and-time-fields-into-one/m-p/199502#M57773</link>
    <description>&lt;P&gt;After you combine the fields use convert mktime to convert the time from human readable to epoch.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Convert"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Convert&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Sep 2014 00:31:22 GMT</pubDate>
    <dc:creator>kbecker</dc:creator>
    <dc:date>2014-09-03T00:31:22Z</dc:date>
    <item>
      <title>How to combine two separate date and time fields into one timestamp field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-combine-two-separate-date-and-time-fields-into-one/m-p/199499#M57770</link>
      <description>&lt;P&gt;Hi, I have two separate fields that I'd like to combine into 1 timestamp field.&lt;/P&gt;

&lt;P&gt;The fields are formatted "YYMMDD" and "HHMMSS"&lt;/P&gt;

&lt;P&gt;I'd like to combine and eval them to read "mm/dd/yyyy hh:mm:ss".&lt;/P&gt;

&lt;P&gt;Does anyone have any experience with this? The fields are "TRADE_YYMMDD" and "EXEC_TIME_HHMMSS"&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:27:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-combine-two-separate-date-and-time-fields-into-one/m-p/199499#M57770</guid>
      <dc:creator>bcusick</dc:creator>
      <dc:date>2020-09-28T17:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to combine two separate date and time fields into one timestamp field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-combine-two-separate-date-and-time-fields-into-one/m-p/199500#M57771</link>
      <description>&lt;P&gt;You can use the eval function for example &lt;/P&gt;

&lt;P&gt;| eval combined = TRADE_YYMMDD." ".EXEC_TIME_HHMMSS&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:27:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-combine-two-separate-date-and-time-fields-into-one/m-p/199500#M57771</guid>
      <dc:creator>kbecker</dc:creator>
      <dc:date>2020-09-28T17:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to combine two separate date and time fields into one timestamp field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-combine-two-separate-date-and-time-fields-into-one/m-p/199501#M57772</link>
      <description>&lt;P&gt;Thanks..I can combine the fields, but how about getting them into epoch? I fear that just throwing them together won't give me the correct time that I can convert correctly..or am I looking too far into this?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2014 00:10:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-combine-two-separate-date-and-time-fields-into-one/m-p/199501#M57772</guid>
      <dc:creator>bcusick</dc:creator>
      <dc:date>2014-09-03T00:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to combine two separate date and time fields into one timestamp field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-combine-two-separate-date-and-time-fields-into-one/m-p/199502#M57773</link>
      <description>&lt;P&gt;After you combine the fields use convert mktime to convert the time from human readable to epoch.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Convert"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Convert&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2014 00:31:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-combine-two-separate-date-and-time-fields-into-one/m-p/199502#M57773</guid>
      <dc:creator>kbecker</dc:creator>
      <dc:date>2014-09-03T00:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to combine two separate date and time fields into one timestamp field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-combine-two-separate-date-and-time-fields-into-one/m-p/199503#M57774</link>
      <description>&lt;P&gt;If you have (as &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240"&gt;@kbecker&lt;/a&gt; shows) created a field which holds the combined date and time information, you can get the epoch representation like so;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your_search 
| eval combined_epoch = strptime(combined, "%y%m%d %H%M%S") 
| eval nice_date = strftime(combined_epoch, "%m/%d/%y %H:%M:%S")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Note that it is important that the strptime variables actually match the contents of the field &lt;CODE&gt;combined&lt;/CODE&gt;. In this case  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;140823 095421
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;is ok, but none of the following will work;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;20140823 09:54:21
14.08.23 095421
2014-08-23 09:54:21
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So basically you need to look at the data you have, and specify how &lt;STRONG&gt;parse&lt;/STRONG&gt; the time string into epoch (str*&lt;EM&gt;p&lt;/EM&gt;&lt;EM&gt;time). Then you can decide yourself how you want to **format&lt;/EM&gt;* the epoch timestamp (str*&lt;EM&gt;f&lt;/EM&gt;*time).&lt;/P&gt;

&lt;P&gt;See the docs, or link below for common variables;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.strftime.net" target="_blank"&gt;http://www.strftime.net&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:28:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-combine-two-separate-date-and-time-fields-into-one/m-p/199503#M57774</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2020-09-28T17:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to combine two separate date and time fields into one timestamp field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-combine-two-separate-date-and-time-fields-into-one/m-p/199504#M57775</link>
      <description>&lt;P&gt;So far so good on this one. The only discrepency I am seeing is the fact that it contains a "zero" in the month if it's a single-digit month. Is there any way to get rid of that?&lt;/P&gt;

&lt;P&gt;sourcedata: 140823 090421&lt;/P&gt;

&lt;P&gt;New field: 08/23/2014 09:54:21 AM&lt;/P&gt;

&lt;P&gt;And what I'm looking for is: 8/23/2014 9:54:21 AM. It just needs to be an exact match to an already existing field in this format. Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2014 18:37:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-combine-two-separate-date-and-time-fields-into-one/m-p/199504#M57775</guid>
      <dc:creator>bcusick</dc:creator>
      <dc:date>2014-09-04T18:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to combine two separate date and time fields into one timestamp field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-combine-two-separate-date-and-time-fields-into-one/m-p/199505#M57776</link>
      <description>&lt;P&gt;&lt;CODE&gt;%e&lt;/CODE&gt; is for days 1..31,&lt;BR /&gt;
instead of &lt;CODE&gt;%d&lt;/CODE&gt;, which is 01..31&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2014 19:18:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-combine-two-separate-date-and-time-fields-into-one/m-p/199505#M57776</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2014-09-04T19:18:55Z</dc:date>
    </item>
  </channel>
</rss>

