Splunk Enterprise

Problem converting some dates to epoch

Gabriel_CCI
Explorer

Hi.

I have a problem with strptime
I try converter a date with

datee1=strptime('datee', "%d-%b-%y") but with some dates don´t work
example

datee                                   datee1

31-ago-16                      
13-feb-19                        1550026800.000000

When I overwrite  31-ago-16 with 13-fe-19  it works!
I don´t understand

My source is a Lookup file


Labels (1)
0 Karma
1 Solution

kamlesh_vaghela
SplunkTrust
SplunkTrust

@Gabriel_CCI 

 

Your data has invalid mon, ago is not valid month name in date 31-ago-16 , That's Y it is not working.

 

https://docs.splunk.com/Documentation/Splunk/8.2.1/SearchReference/Commontimeformatvariables

 

View solution in original post

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@Gabriel_CCI 

 

Your data has invalid mon, ago is not valid month name in date 31-ago-16 , That's Y it is not working.

 

https://docs.splunk.com/Documentation/Splunk/8.2.1/SearchReference/Commontimeformatvariables

 

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...