Getting Data In

How to modify the time stamp format when i run a scheduled pdf?

ppurokit
Path Finder

I have a dashboard which has some 6 items as part of it.

I have a scheduled to email the dashboard every 24 hours.

The Dashboard name is "cpy001_daily_reports_"

When i receive the email in pdf I see that the attachment has the date appended to it as "cpy001_daily_reports_-2013-04-23.pdf"

But i have to modify the above time stamp format which is getting appended to the attachment and i want it in the following format as "_"

Please let me know how will i be able to change the time stamp format here ?

0 Karma
1 Solution

TimMc
Explorer

You could change the following line in $SPLUNK_HOME/etc/apps/search/bin/sendemail.py:

datestamp = time.strftime('%Y-%m-%d')

To something like this:

datestamp = time.strftime('%Y%m%d%H%M%S')

This solution might not be supportable going forward if sendemail.py is overwritten by a newer version of Splunk during an update.

Feature request?

See also:

Tim.

View solution in original post

TimMc
Explorer

You could change the following line in $SPLUNK_HOME/etc/apps/search/bin/sendemail.py:

datestamp = time.strftime('%Y-%m-%d')

To something like this:

datestamp = time.strftime('%Y%m%d%H%M%S')

This solution might not be supportable going forward if sendemail.py is overwritten by a newer version of Splunk during an update.

Feature request?

See also:

Tim.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...