Getting Data In

set up a new field for timestamp - not working

premraj_vs
Path Finder

I am running a search against JSON data, and I am able to get the field I am interested in. Now, I am trying to set that field as a timestamp for charts, but it is not working.

index=idx-index-name "fields.created"="*"
| eval _time=strptime("fields.created","%Y-%m-%dT%H:%M:%SZ")
| timechart span=1d count

Value of field - "fields.created" - 2019-01-09T10:51:34.000-0500

If I remove the second line and run the command, all the events are in index time ( today ), but the records are from the last 1 month.

Can someone help me find what i am missing?

0 Karma
1 Solution

chrisyounger
SplunkTrust
SplunkTrust

Hi @premraj_vs

Give this a try:

 index=idx-index-name "fields.created"="*"
 | eval _time=strptime('fields.created',"%Y-%m-%dT%H:%M:%SZ")
 | timechart span=1d count

Sometimes you need to use single quotes when referring to field names that have strange characters in them.

All the best

View solution in original post

chrisyounger
SplunkTrust
SplunkTrust

Hi @premraj_vs

Give this a try:

 index=idx-index-name "fields.created"="*"
 | eval _time=strptime('fields.created',"%Y-%m-%dT%H:%M:%SZ")
 | timechart span=1d count

Sometimes you need to use single quotes when referring to field names that have strange characters in them.

All the best

premraj_vs
Path Finder

It worked .. Thanks for the help

0 Karma

chrisyounger
SplunkTrust
SplunkTrust

OK Looks like your strptime format is wrong. Try this one instead: %Y-%m-%dT%H:%M:%S.%3Q%z

0 Karma

premraj_vs
Path Finder

yes i made this change

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...