Splunk Search

Can you help me convert a field value extracted by a rex command to another date time format?


Hello Community,

I have certain field values extracted by using rex command. The timestamp format of the field value is in ISO 8601.
For example -


I need to convert it in the following format

%m-%d-%Y %H:%M:%S %p

I tried using strftime but that doesn't work. Gives blank results. Can somebody please help me with some pointers?


0 Karma

Community Manager
Community Manager

Hi @ameyapatil29

Glad you got an answer by @493669 below. I noticed you upvoted his answer, but didn't accept it. If it solved your question, please don't forget to resolve the post by clicking "Accept" directly below his answer.


0 Karma

Super Champion

Try this run anywhere search:

|makeresults|eval t="2018-09-24T04:41:54Z"|eval b=strftime(strptime(t,"%Y-%m-%dT%H:%M:%SZ"),"%m-%d-%Y %H:%M:%S %p")
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!