Splunk Enterprise

time stamp

shreyasamin64
Explorer

Hello, 

need assistance on time format 

input :                                                              output :  %F    (2021-11-23)

23 Nov

11/23/21

11/23/2021

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

here is list of those abbreviations https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Commontimeformatvariables

You could convert those from string to epoch with strptime and from epoch to string with strftime.

| makeresults 
| eval time1="23 Nov", time2="11/23/21", time3="11/23/2021"
| eval time1s=strftime(strptime(time1,"%d %b"),"%F"),
time2s=strftime(strptime(time2,"%m/%d/%y"),"%F"),
time3s=strftime(strptime(time3,"%m/%d/%Y"),"%F")
| table time1 time1s time2 time2s time3 time3s

r. Ismo 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...