Getting Data In

How to remove hh:mm:ss from a date/time field to be displayed in mm/dd/yyyy format?

dennisSplunk201
New Member

So my original data looks like this:
AUDIT_CREATED_TS
7/17/2018 1:15:30 AM
7/17/2018 1:10:30 AM
7/17/2018 1:05:41 AM
:
:

But how do I change the data into this format via Splunk?
AUDIT_CREATED_TS
7/17/2018
7/17/2018
7/17/2018
:
:

Using this still does not help me:

...| convert timeformat="%m/%d-%Y" ctime(AUDIT_CREATED_TS) AS ctime

Doing this does not work too (AUDIT_CREATED_TS still in "%m/%d/%Y %H:%M:%S %AM/%PM" format, not %m/%d/%Y format I want)

... | eval AUDIT_CREATED_TS=strftime(AUDIT_CREATED_TS,"%m/%d/%Y")
0 Karma
1 Solution

cpetterborg
SplunkTrust
SplunkTrust

A simple and fast (efficient) way is with rex:

... | rex mode=sed field=AUDIT_CREATED_TS "s/\s.*//"

It doesn't have to do any time calculations, just some simple string substitution.

View solution in original post

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

A simple and fast (efficient) way is with rex:

... | rex mode=sed field=AUDIT_CREATED_TS "s/\s.*//"

It doesn't have to do any time calculations, just some simple string substitution.

0 Karma

dennisSplunk201
New Member

This is super helpful, thanks 🙂

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Your last eval was close, but AUDIT_CREATED_TS is already in text form so strftime won't work on it. You need to convert to epoch form and then to the desired text form. Try this.

... | eval AUDIT_CREATED_TS=strftime(strptime(AUDIT_CREATED_TS, "%m/%d/%Y %I:%M:%S %p"), "%m/%d/%Y")
---
If this reply helps you, Karma would be appreciated.

dennisSplunk201
New Member

Thanks! This really helped!

0 Karma

auraria1
Path Finder

This has already been answered but you can also use the replace function.

| eval time=replace(AUDIT_CREATED_TS, ":","/")

This will replace the colons in that field with forward slashes and place the output into a field called time.

0 Karma

dennisSplunk201
New Member

I accept your solution as well.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...