Splunk Search

Can you help me to extract a date field?

Explorer

Hello Splunkers,

I need to extract only the date with the below logs in format mm/dd/yyyy. Could you please assist? Thanks

Tue Apr 02 00:00:00 EDT 2019

0 Karma

SplunkTrust
SplunkTrust

Try this:

... | eval date=strftime( strptime(<datetime field>, "%b %a %d %H:%M:%S %Z %Y"), "%m/%d/%Y") | ...
---
If this reply helps you, an upvote would be appreciated.
0 Karma