Reporting

How to extract timestamp from file name

ravir_jbp
Explorer

I have a event that are generated in csv format with timestamp within file name as mentioned below. Need to extract timestamp from the file and create new column as _time. Need rex query to extract the YYYY-MM-DD HH:MM:SS.

 

D:\automation\miscprocess\test_utilization_info_20240618_195509.csv

Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Do you mean you have loaded the csv into a lookup or that the csv has been ingested into an index and there is a source field associated with each event with the file name in?

0 Karma

ravir_jbp
Explorer

The CSV files are generated by automation which generated the server status with filename when the file was generated.  There is not timestamp generated in the file so I have to use file generation time stamp in the naming convention.

ravir_jbp_0-1719571146186.png

 

0 Karma

ravir_jbp
Explorer

This is file content. This contnt does not have timestamp for each entries. So I have to use the file timestmap for each entries within csv file

 

ravir_jbp_0-1719571415144.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex field=source "info_(?<timestamp>\d{8}_\d{6})\.csv"
| eval _time=strptime(timestamp,"%Y%m%d_%H%M%S")
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...