12/02/2015 12:00:00 AM, Execute time: 0150
looking to extract the date and the 24hr time pls
See here for the time format variables
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Commontimeformatvariables
Assuming the date is month/day/year and the time is a 12 hour clock (not 24 hour as you say), try
TIME_FORMAT = %m/%d/%Y %I:%M:%S %p
it is definitely 24h - thanks i'll try first thing in the morn
If its 24 hours, why does it have a AM/PM ? 16:00:00 AM wouldn't make much sense!
i see your point - however, further entries:
12/02/2015 12:00:00 AM, Execute Time: 1415
12/02/2015 12:00:00 AM, Execute Time: 1500
12/02/2015 12:00:00 AM, Execute Time: 1515
12/02/2015 12:00:00 AM, Execute Time: 1315
Try this:
rex field=_raw "(?ms)^(?P\d{2}\/\d{2}\/\d{4}\s+\d{2}:\d{2}:\d{2}\s+\w{2})"
You can use Splunk's "Extract Fields" from Event Actions to perform the same.
hi thanks - i'm trying to do this in a props.conf file - not in a search