I have an input file that has lines like:
Splunk is accounting for the time correctly in AM/PM however the data_hour values are all being kept in the 12 hour format; so when plotting and selecting for instance out of business hours we don't get good results because we never get an hour value above 12. 1300 to 2400 are lost with the PM.
Any ideas how to get hours back to a 24 hour clock?
Almost the same results here...
_time date_hour hour _raw
2015-12-31 02:54:00 2 02 12/31/2015,02:54PM,5074576000,1,xyzname
I would expect date_hour to come back as 14... the eval above bring back a padded 0 value of the same