- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to group fields and convert time to readable format?
_Raj
Loves-to-Learn Lots
09-29-2022
09:46 AM
My task is like I need to group by two fields i.e eventid and dest make it happened at firsttime and lasttime
eventid dest count firsttime lasttime
256 drdydyf.google.com 56 2022-09-28T19:21:10 2022-09-28T19:21:34
249 bigdaddy.com 78 2022-09-28T19:22:10 2022-09-28T19:22:20
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
09-29-2022
01:27 PM
Is those the current results or the desired results? Is the former then what are the desired results? What do you mean by "readable"? ISO8601 is perfectly readable, IMO. What format do you want.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
