Splunk Search

Calculate epoch date from a month name

skooby
Explorer

I have a date field "Expiry" that comes in this lovely format:

To: Thursday, 17 July 2036 00:59:59 o'clock BST

I could work out an epoch date easily from e.g.
17/07/2036 00:59:59 using

eval Expiry_Epoch=strptime(Expiry, "%d/%m/%y %H:%M:%s")

but %m only recognises a numerical, not an alphabetical month.

Does anyone know how I can recognise an alphabetical month like "July"?

Thank

Tags (3)
0 Karma

somesoni2
Revered Legend

Try this

| eval Expiry_Epoch=strptime(Expiry, "%A, %d %B %Y %H:%M:%S o'clock %Z")
0 Karma

strive
Influencer
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...