Getting Data In

Need Time_Format value

VijaySrrie
Builder
Hi, I have two different time values 2020-06-24 03:07:39,997Z 2020-06-24 03:07:39.990Z The first value has a comma(,) and the second value has a dot(.) How can I parse both the values. Any documentation on this?
Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @VijaySrrie ,

you can leave Splunk to use the correct Time format without forcing a TIME_FORMAT in props.conf.

If Splunk doesn't know one of them add it to datetime.xml following the instructions at https://docs.splunk.com/Documentation/SplunkCloud/8.0.2004/Data/Configuredatetimexml

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @VijaySrrie ,

you can leave Splunk to use the correct Time format without forcing a TIME_FORMAT in props.conf.

If Splunk doesn't know one of them add it to datetime.xml following the instructions at https://docs.splunk.com/Documentation/SplunkCloud/8.0.2004/Data/Configuredatetimexml

Ciao.

Giuseppe

gcusello
SplunkTrust
SplunkTrust

Hi @VijaySrrie ,

Perfect!

If you appreciate this solution you can also leave a Karma Point .

Ciao and next time.

Giuseppe

kamlesh_vaghela
SplunkTrust
SplunkTrust

@VijaySrrie 

 

You can go through this link.

https://docs.splunk.com/Documentation/Splunk/8.0.4/SearchReference/Commontimeformatvariables

Please  check my sample search with your provided data.

 

| makeresults | eval date="2020-06-24 03:07:39,997Z|2020-06-24 03:07:39.990Z" , date=split(date,"|") | mvexpand date | eval epochtime = strptime(date,"%Y-%m-%d %M:%H:%S,%3QZ")  | eval ReIterated = strftime(epochtime,"%Y-%m-%d %M:%H:%S,%3QZ") | table date epochtime ReIterated

 

Hope this will help you.

 

Thanks
Kamlesh Vaghela

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...