Hello,
I add an CSV data into my splunk without any timestamp and SPLUNK add automatiquely an timestamp with the format "3/16/22 4:33:55.000 PM" I would like change the date on the format "3/16/22" how can I do that ?
Regards,
Can you please provide sample data or screenshot of which timestamp you are talking about?
And also how you have added the CSV in Splunk.
You Can try Like this,| eval timeformat=strftime(_time,"%m/%d/%y")