Dashboards & Visualizations

Why is the timestamp format displayed on the dashboard different from the exported PDF output?

billycote
Path Finder

I have a dashboard that I am exporting out to a PDF on a schedule. The search works fine, the dashboard looks fine, the e-mail works fine, but I have one small problem. On the dashboard I see this

2015-09-30 09:30:00     wednesday   cg1-r-fid-oma-l2    7602398 

On the PDF export I see this:

2015-09-30T09:30:00-0400 wednesday cg1-r-fid-oma-l2 7602398

I can understand what the PDF means. I just don't want to see the -0400 (timezone offset I believe) It would be much more clear if it looked just like it did on the dashboard. Is there a format somewhere that I'm missing?

0 Karma
1 Solution

billycote
Path Finder

looks like it was answered in another post.

It looks like Splunk is smart about _time and shows it the way that the user would want but on the export it adds formatting characters. I imagine it would be so that someone could programatically calculate time, etc. But the answer I found and it worked was to change the format in the dashboard firt:

| eval mytime = strftime(_time, "%Y-%m-%d %H:%M:%S")

View solution in original post

0 Karma

billycote
Path Finder

looks like it was answered in another post.

It looks like Splunk is smart about _time and shows it the way that the user would want but on the export it adds formatting characters. I imagine it would be so that someone could programatically calculate time, etc. But the answer I found and it worked was to change the format in the dashboard firt:

| eval mytime = strftime(_time, "%Y-%m-%d %H:%M:%S")

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...