Splunk Search

Can I use an extracted date field as my _time for my time chart?

shariinPH
Contributor

Splunk indexed my data and gets the timestamp by its Date Modified (modtime)
Now in my events, I also have an extracted date field with the format MM/DD/YYYY
I've got to get that date field to use on my timechart.

Can I use that extracted date field as my _time for my time chart? Is it possible?

Thanks 🙂

0 Karma
1 Solution

tom_frotscher
Builder

I see two possible solutions:

1) You reconfigure your inputs.conf and props.conf, to make splunk recognize your date field and use it to determine _time.

2) You do some search magic to use an other field as _time for your timechart. I think what you can do ist to use an eval command to store the information of an other field in your _time field:

... | eval _time = 'extracted_date_field' | timechart ...

Keep in mind, that your extracted_date_field should be an epoch. Therefore you might have to use the strptime command before:

... | eval extracted_date_field = strptime('extracted_date_field', "%m/%d/%Y") | eval _time = 'extracted_date_field' | timechart ...

Havn't tested it, but i think something like this should work.

Grettings

Tom

View solution in original post

tom_frotscher
Builder

I see two possible solutions:

1) You reconfigure your inputs.conf and props.conf, to make splunk recognize your date field and use it to determine _time.

2) You do some search magic to use an other field as _time for your timechart. I think what you can do ist to use an eval command to store the information of an other field in your _time field:

... | eval _time = 'extracted_date_field' | timechart ...

Keep in mind, that your extracted_date_field should be an epoch. Therefore you might have to use the strptime command before:

... | eval extracted_date_field = strptime('extracted_date_field', "%m/%d/%Y") | eval _time = 'extracted_date_field' | timechart ...

Havn't tested it, but i think something like this should work.

Grettings

Tom

shariinPH
Contributor

will try this one. thanks tom!

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...