Splunk Search

How to extract month and year from _time

sbhatnagar88
Path Finder

_ time is in below format

2019-01-30 07:10:51.191
2019-01-30 07:10:51.190
2019-01-30 07:10:51.189

I need output in below format

January 2019

Any help would be highly appreciable...

Tags (1)
0 Karma
1 Solution

DMohn
Motivator

Try this:

<your base search> | eval yourtime = strftime(_time,"%B %Y) 

the field yourtime will then contain the timestamp in the requested format.

View solution in original post

vishaltaneja070
Motivator

Hello @sbhatnagar88

Try this:
index=_internal | head 1 | table _time | eval time= strftime(_time, "%B %Y")

sbhatnagar88
Path Finder

Thank you...

DMohn
Motivator

Try this:

<your base search> | eval yourtime = strftime(_time,"%B %Y) 

the field yourtime will then contain the timestamp in the requested format.

sbhatnagar88
Path Finder

Thank you...

0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk Observability Cloud – June 2025

What’s New in Splunk Observability Cloud – June 2025 We are excited to announce the latest enhancements to ...

Almost Too Eventful Assurance: Part 2

Work While You SleepBefore you can rely on any autonomous remediation measures, you need to close the loop ...

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

 Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research Team (STRT) and ...