Getting Data In

How to get the right time?

veveok
Engager

my log appear:

 

1;1;laptop-rdvt90t4;http://update-software.xxx.com/WeatherFix03_SP03120.exe;C:\Windows\SysWOW64\DynamicWeather.exe;NT AUTHORITY\SYSTEM;2022-05-02 09:23:25;192.168.1.8;;;

1;1;laptop-rdv7446p;http://update-software.xxx.com/qatherFixP00190.exe;C:\Windows\SysWOW64\Der.exe;ScWhJ\lizonghao;2022-05-02 09:25:27;192.168.1.8;;;

I use :strptime()  %H:%M:%S , and reg “202\d+-\d+\-\d+\s” to get the time,

2.jpg

 

but it look like wrong。

like this pic.

 

1.jpg

 

how to write this reg to get the  time?

 

Labels (1)
Tags (1)
0 Karma
1 Solution

veveok
Engager

it works with:

%Y-%m-%d %H:%M:%S

and

^(?:[^;]*\;){10}\s*

 

 

View solution in original post

0 Karma

veveok
Engager

it works with:

%Y-%m-%d %H:%M:%S

and

^(?:[^;]*\;){10}\s*

 

 

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...