I am using a single value in a dashboard, it is only showing a date, but I cannot get the date to format the way want it on the dashboard. My search string is: index=conmon earliest=11/23/2022:00:00:00 dedup LASTMODIFIED eval tst = strftime(strptime(LASTMODIFIED, %Y-%m-%d), %Y-%m-%d) fields tst
want 11-23-2022 , but continue to get 2022-11-23T13:35:53-05:00
The search on its own brings back the value correctly, but not on the dashboard. Any help would b greatly appreciated.
Bill K
richgalloway, maybe this makes more sense, here is my search string: index=conmon earliest>="12/05/2022:00:00:00" | dedup _time | eval mytime=strftime(_time, "%F") | table mytime
as a search I get back the value correctly, when I use this search in a dashboard singlevalue panel, i get utc with time as the value showing
I can't reproduce this problem. The query displays times in my selected time zone in both the search window and in a dashboard.
richgalloway, changing the format did not help. LASTMODIFIED doe snot come up as a choice, just _time or tst(null) as the selected data field. it is date time. but a string in the data itself
What do you mean by "LASTMODIFIED does not come up as a choice"? Is LASTMODIFIED a field? If not then why is it in the query?
Please share sanitized sample events if you need help extracting LASTMODIFIED.
The format string in strftime is incorrect. Try "%m-%d-%Y".
index=conmon earliest=11/23/2022:00:00:00
| dedup LASTMODIFIED
| eval tst = strftime(strptime(LASTMODIFIED, "%Y-%m-%d"), "%m-%d-%Y")
| fields tst
That depends, however, on the format of the LASTMODIFIED field. Would you please share that?