Splunk Search

Extrating fields with the single dates of the month?

sympatiko
Communicator

Hi Splunkers,

Im having this serious problem. Is there any way to transform or modify a log coming to a certain index?

Example: I have logs like this:

Jul 1 08:00:00 user service : example logs

I want to modify into :

07-01 08:00:00 user service : example logs

Is this possible? Im going to do log extraction for my alerting.

Thanks

Tags (2)
0 Karma

vganjare
Builder
0 Karma

sympatiko
Communicator

Hi vganjare,

Im very newbie at splunk and there are some terms that made me confused. Can you give me some sample?

Thanks

0 Karma

vganjare
Builder

Lets take this example:
Jul 1 08:00:00 ==> %b %d %H:%M:%S (refer to http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Commontimeformatvariables)

07-01 08:00:00 ==> %m-%d %H:%M:%S

Your query should look like:
...... | eval customTime = strftime(_time, "%m-%d %H:%M:%S")

Check the examples of strftime and strptime at http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/CommonEvalFunctions

0 Karma

sympatiko
Communicator

Because I configured an alerting with field extraction. So I only notice now that Every 1-9 of the month the logs has a space between the month and the day.

Sample : Jul 1 .......

It has extra space so it causes my custom alerts to read the different parameter based on my extracted fields on my query.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...