Splunk Dev

Remove Timezone information from datetime field using spath while reading data from json file

Skhunte
Engager

Hi team,

I am extracting JSON data using spath. There is done datetime field and which is coming with zone name as below.

Skhunte_0-1604500410305.pngSkhunte_0-1604500410305.png

 

I want it without UTC word. like 2020-11-03 10:10:10 

Can we do this using spath.

if yes please provide me example.

 

thank you for your help.

Sanket K

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Can you post your original json?

Skhunte
Engager

Thank you for your comment. 

to be honest i don't have JSON now because I am getting CSV as source which has JSON as source.

I have to suggest solution to trim zone factor. 

If you can take any JSON file for sample which has time with zone as mentioned in my original post that will help me.

Thank you agian.

Sanket

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...