I try to transform a date string, into a date, to enable splunk to sort it.
Here is a sample :
Hi tried :
eval n=strftime(field, " %Y-%m-%dT%H:%M:%SZ")
But it doesn't work. Why ? What would be the best way to do this ?
Is there a way to automate the conversion at searchtime ?
At index Time, splunk is able to reconize Timeformat automatically, is there a way to use the same recognition an search time, with "convert" for example ?
I have 4 different Timeformat for the same field, and I want to be able to convert it in one way...:
if I use
| convert auto()
I only get the year...
But somehow Splunk is able to handle this by indexing, maybe a function is missing being able to use it a search time ?
This worked fine for me, I think you have an accidental space character before the "%Y" :
...| eval foo="2013-01-17T09:35:49Z" | eval goo=strptime(foo,"%Y-%m-%dT%H:%M:%SZ") | table goo