Hi Everyone,
I have one field called BuildStartDate. Its showing Dates like below:
Mon Jan 11 09:00:13 MST 2021
Sun Jan 10 09:00:01 MST 2021
I want only to Display BuildStartDate in following Format
Mon Jan 11 2021
Sun Jan 10 2021
Can someone guide me how can I do that.
Thanks in advance
There was a typo in my query, there shouldn't be space after field=
Please try below;
index="abc" sourcetype="xyzt" BuildName!="g*" (BuildResult ="*")
| eval TimeTaken=round('BuildDuration'/1000)
| fieldformat TimeTaken = tostring(TimeTaken, "duration")
| rex mode=sed field=BuildStartDate "s/\d{2}:\d{2}:\d{2}\s[A-Z]{3}\s//g"
| table ORG BuildResult BuildStartDate TimeTaken
| where ORG="gcp"
If this reply helps you an upvote is appreciated.
There was a typo in my query, there shouldn't be space after field=
Please try below;
index="abc" sourcetype="xyzt" BuildName!="g*" (BuildResult ="*")
| eval TimeTaken=round('BuildDuration'/1000)
| fieldformat TimeTaken = tostring(TimeTaken, "duration")
| rex mode=sed field=BuildStartDate "s/\d{2}:\d{2}:\d{2}\s[A-Z]{3}\s//g"
| table ORG BuildResult BuildStartDate TimeTaken
| where ORG="gcp"
If this reply helps you an upvote is appreciated.
Hi @aditsss,
You can use below query;
| rex mode=sed field= BuildStartDate "s/\d{2}:\d{2}:\d{2}\s[A-Z]{3}\s//g"
If this reply helps you an upvote is appreciated.
I tried like that but getting error in rex.
Can you guide me where I am wrong:
index="abc" sourcetype="xyzt" BuildName!="g*" (BuildResult ="*")|eval TimeTaken=round('BuildDuration'/1000) | fieldformat TimeTaken = tostring(TimeTaken, "duration")| rex mode=sed field= BuildStartDate "s/\d{2}:\d{2}:\d{2}\s[A-Z]{3}\s//g"|table ORG BuildResult BuildStartDate TimeTaken| where ORG="gcp"
Getting below Error:
Error in 'rex' command: Failed to initialize sed. cannot find sed command: B
Can you guide me where I am wrong.
Thanks in advance