Splunk Search

Can I use an extracted date field as my _time for my time chart?

shariinPH
Contributor

Splunk indexed my data and gets the timestamp by its Date Modified (modtime)
Now in my events, I also have an extracted date field with the format MM/DD/YYYY
I've got to get that date field to use on my timechart.

Can I use that extracted date field as my _time for my time chart? Is it possible?

Thanks 🙂

0 Karma
1 Solution

tom_frotscher
Builder

I see two possible solutions:

1) You reconfigure your inputs.conf and props.conf, to make splunk recognize your date field and use it to determine _time.

2) You do some search magic to use an other field as _time for your timechart. I think what you can do ist to use an eval command to store the information of an other field in your _time field:

... | eval _time = 'extracted_date_field' | timechart ...

Keep in mind, that your extracted_date_field should be an epoch. Therefore you might have to use the strptime command before:

... | eval extracted_date_field = strptime('extracted_date_field', "%m/%d/%Y") | eval _time = 'extracted_date_field' | timechart ...

Havn't tested it, but i think something like this should work.

Grettings

Tom

View solution in original post

tom_frotscher
Builder

I see two possible solutions:

1) You reconfigure your inputs.conf and props.conf, to make splunk recognize your date field and use it to determine _time.

2) You do some search magic to use an other field as _time for your timechart. I think what you can do ist to use an eval command to store the information of an other field in your _time field:

... | eval _time = 'extracted_date_field' | timechart ...

Keep in mind, that your extracted_date_field should be an epoch. Therefore you might have to use the strptime command before:

... | eval extracted_date_field = strptime('extracted_date_field', "%m/%d/%Y") | eval _time = 'extracted_date_field' | timechart ...

Havn't tested it, but i think something like this should work.

Grettings

Tom

shariinPH
Contributor

will try this one. thanks tom!

0 Karma
Get Updates on the Splunk Community!

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...

Cloud Platform | Discontinuing support for TLS version 1.0 and 1.1

Overview Transport Layer Security (TLS) is a security communications protocol that lets two computers, ...

New Customer Testimonials

Enterprises of all sizes and across different industries are accelerating cloud adoption by migrating ...