Splunk indexed my data and gets the timestamp by its Date Modified (modtime)
Now in my events, I also have an extracted date field with the format MM/DD/YYYY
I've got to get that date field to use on my timechart.
Can I use that extracted date field as my _time for my time chart? Is it possible?
Thanks 🙂
I see two possible solutions:
1) You reconfigure your inputs.conf and props.conf, to make splunk recognize your date field and use it to determine _time.
2) You do some search magic to use an other field as _time for your timechart. I think what you can do ist to use an eval command to store the information of an other field in your _time field:
... | eval _time = 'extracted_date_field' | timechart ...
Keep in mind, that your extracted_date_field should be an epoch. Therefore you might have to use the strptime command before:
... | eval extracted_date_field = strptime('extracted_date_field', "%m/%d/%Y") | eval _time = 'extracted_date_field' | timechart ...
Havn't tested it, but i think something like this should work.
Grettings
Tom
I see two possible solutions:
1) You reconfigure your inputs.conf and props.conf, to make splunk recognize your date field and use it to determine _time.
2) You do some search magic to use an other field as _time for your timechart. I think what you can do ist to use an eval command to store the information of an other field in your _time field:
... | eval _time = 'extracted_date_field' | timechart ...
Keep in mind, that your extracted_date_field should be an epoch. Therefore you might have to use the strptime command before:
... | eval extracted_date_field = strptime('extracted_date_field', "%m/%d/%Y") | eval _time = 'extracted_date_field' | timechart ...
Havn't tested it, but i think something like this should work.
Grettings
Tom
will try this one. thanks tom!