Getting Data In

Convert time to another timezone then remove timezone identifier

michaelrosello
Path Finder

So I have multiple fields that have time value that looks like this.

2017-10-05T16:00:00Z

What I want is to convert it to GMT+8 then remove the extra parts and retain just the date instead using props.conf

2017-10-06

10-5 UTC converted to GMT+8 is 10-6

0 Karma

abhijeet01
Path Finder

Hi michaelrosello,

Please check below link. It will help you.
https://answers.splunk.com/answers/320021/how-do-i-set-timezone-properly-in-propsconf.html

0 Karma

harsmarvania57
Ultra Champion

Hi,

Can you please try below sample query (First line is used to generate dummy data)

| makeresults | eval field1="2017-10-05T16:00:00Z" 
| eval new_field=strftime(strptime(field1,"%Y-%m-%dT%H:%M:%SZ")+28800,"%Y-%m-%d")

I have created above query for single field only, if you have multiple field then you need to repeat for each field.

0 Karma

michaelrosello
Path Finder

It work but I'm trying looking at using props.conf as there is 23 fields to be exact that I need to convert.

0 Karma

harsmarvania57
Ultra Champion

You can use below configuration in props.conf on Search head. In below configuration field1 contains actual timestamp and it will create new field with name new_field

[yoursourcetype]
EVAL-new_field = strftime(strptime(field1,"%Y-%m-%dT%H:%M:%SZ")+28800,"%Y-%m-%d")

EDIT: You need to repeat same config for 23 times so something like this

[yoursourcetype]
EVAL-new_field1 = strftime(strptime(field1,"%Y-%m-%dT%H:%M:%SZ")+28800,"%Y-%m-%d")
EVAL-new_field2 = strftime(strptime(field2,"%Y-%m-%dT%H:%M:%SZ")+28800,"%Y-%m-%d")
.........
.........
EVAL-new_field23 = strftime(strptime(field23,"%Y-%m-%dT%H:%M:%SZ")+28800,"%Y-%m-%d")
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...