Getting Data In

How to use strptime for a time field in the format hhmm?

svercelli
Path Finder

In my new data set, the time comes in the format 1652 as it relates to 4:52pm. However, when it is before 1AM it comes in simply as 52 representing 12:52am. What would a strptime look like for this or is it even possible?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Strptime will not accept "52" using "hhmm" as a format string.

I hope by "new data set" you mean this is recent development work. If so, go back the developer and ask for a proper time field.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk Observability Cloud – June 2025

What’s New in Splunk Observability Cloud – June 2025 We are excited to announce the latest enhancements to ...

Almost Too Eventful Assurance: Part 2

Work While You SleepBefore you can rely on any autonomous remediation measures, you need to close the loop ...

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

 Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research Team (STRT) and ...