Splunk Search

Can I use an extracted date field as my _time for my time chart?

shariinPH
Contributor

Splunk indexed my data and gets the timestamp by its Date Modified (modtime)
Now in my events, I also have an extracted date field with the format MM/DD/YYYY
I've got to get that date field to use on my timechart.

Can I use that extracted date field as my _time for my time chart? Is it possible?

Thanks 🙂

0 Karma
1 Solution

tom_frotscher
Builder

I see two possible solutions:

1) You reconfigure your inputs.conf and props.conf, to make splunk recognize your date field and use it to determine _time.

2) You do some search magic to use an other field as _time for your timechart. I think what you can do ist to use an eval command to store the information of an other field in your _time field:

... | eval _time = 'extracted_date_field' | timechart ...

Keep in mind, that your extracted_date_field should be an epoch. Therefore you might have to use the strptime command before:

... | eval extracted_date_field = strptime('extracted_date_field', "%m/%d/%Y") | eval _time = 'extracted_date_field' | timechart ...

Havn't tested it, but i think something like this should work.

Grettings

Tom

View solution in original post

tom_frotscher
Builder

I see two possible solutions:

1) You reconfigure your inputs.conf and props.conf, to make splunk recognize your date field and use it to determine _time.

2) You do some search magic to use an other field as _time for your timechart. I think what you can do ist to use an eval command to store the information of an other field in your _time field:

... | eval _time = 'extracted_date_field' | timechart ...

Keep in mind, that your extracted_date_field should be an epoch. Therefore you might have to use the strptime command before:

... | eval extracted_date_field = strptime('extracted_date_field', "%m/%d/%Y") | eval _time = 'extracted_date_field' | timechart ...

Havn't tested it, but i think something like this should work.

Grettings

Tom

View solution in original post

shariinPH
Contributor

will try this one. thanks tom!

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!