This question might be already answered. But so far I searched I had no luck in understanding how to fix my issue. I worked before coding search syntax with Splunk but never before doing admin stuff inside Splunk.
I have a csv file with some columns and one of them is "Date" field which I want to use to sort the values in my other columns example:
date Total Ransom
I would need to make a count with "Total Ransom" sorted by "Date" is pretty easy, but I cant define Date as _time.
¿How would I be able to do this? I read something about modifying the file datetime.xml , but I want to be sure before I modify a system file.
Thanks for your time in advance!
| inputlookup mylookup.csv | eval NewDate = strptime(Date, "%d/%m/%Y")| sort NewDate | fields - NewDate
So answering to myself. I tried above answers but where not quite what I was looking for.
Although I found how to do it following http://docs.splunk.com/Documentation/Splunk/7.1.2/Data/Configuretimestamprecognition
As simple as to follow properly the formas supported:
strptime() format expression examples
Here are some sample date formats, with the strptime() expressions that handle them:
1998 years, 312 days %Y years, %j days
Jan 24, 2003 %b %d, %Y
January 24, 2003 %B %d, %Y
So when specifying timefield input, go to custom and specify the field that has the "date" and its format.