Hello,
need assistance on time format
input : output : %F (2021-11-23)
23 Nov
11/23/21
11/23/2021
Hi
here is list of those abbreviations https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Commontimeformatvariables
You could convert those from string to epoch with strptime and from epoch to string with strftime.
| makeresults
| eval time1="23 Nov", time2="11/23/21", time3="11/23/2021"
| eval time1s=strftime(strptime(time1,"%d %b"),"%F"),
time2s=strftime(strptime(time2,"%m/%d/%y"),"%F"),
time3s=strftime(strptime(time3,"%m/%d/%Y"),"%F")
| table time1 time1s time2 time2s time3 time3s
r. Ismo