How to format _time field in results email?


Finally got the csv results sent out in emails to only include the relevant info by using the "fields - xxxx,_raw" statement, however, the _time field that's included by default is sent out only as the epoch timestamp.

I'm sure I can use "fields - xxxx,_time,_raw" to get rid of the epoch version, but what would be the syntax to get a FORMATTED timestamp back in the output along the lines of:


for each event line? Looked at the "format" operator, and tried looking up "format _time" and "timestamp formatting output" to no avail in the docs.


Tags (2)
2 Solutions


Pipe it to convert:

| convert ctime(_time) as timestamp 

View solution in original post


And five years later, I was struggling to find the command that formats a field without actually changing the actual value of the field. This five year old answer is one that kept turning up. If anyone still reads this, I would really recommend looking into fieldformat instead. This command has been around since 6.0, so it wasn't available five years ago.

I noticed with convert that you can have some unexpected results, because it changes the sorting order, e.g. in the output of stats, eventhough you might sort before using convert.

Check out fieldformat:

Path Finder

I have used the convert command to format timestamp:

| convert ctime(_time) as datetime timeformat="%d/%m/%Y %H:%M:%S"

0 Karma



Pipe it to convert:

| convert ctime(_time) as timestamp 
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...