Splunk Search

Can you help me to extract a date field?


Hello Splunkers,

I need to extract only the date with the below logs in format mm/dd/yyyy. Could you please assist? Thanks

Tue Apr 02 00:00:00 EDT 2019

0 Karma


Try this:

... | eval date=strftime( strptime(<datetime field>, "%b %a %d %H:%M:%S %Z %Y"), "%m/%d/%Y") | ...
If this reply helps you, an upvote would be appreciated.
0 Karma