Splunk Search

Convert Index time

RASHO
New Member

I am trying to change Event time Apr 02, 2019 3:15:34 AM to YYYY-MM-DD HH:MM:SS,sss format.

Tags (1)
0 Karma

pruthvikrishnap
Contributor

Few things can be done here:
1) Use "convert" in search where you input the current format and can edit the desired output.
https://docs.splunk.com/Documentation/Splunk/7.2.5/SearchReference/Convert
2) Eval function can also do this
https://answers.splunk.com/answers/728399/how-do-i-convert-the-date-format-in-a-custom-field.html
3) from CLI place below parameter in props.conf
[sourcetype]
TIME_FORMAT = %Y-%m-%d %k:%M:%S
in
C:\Program Files\Splunk\etc\system\local\props.conf

0 Karma

somesoni2
Revered Legend

In search (converting the date format in search result)??

0 Karma

vnravikumar
Champion

Hi

Are you trying to convert date field to the specified format? Then try this

| makeresults 
| eval source = "Apr 02, 2019 3:15:34 AM" 
| eval epoch =strptime(source,"%b %d, %Y %H:%M:%S %p") 
| eval newdate=strftime(epoch,"%Y-%m-%d %H:%M:%S %p")

If not please explain your requirement in detail.

0 Karma

RASHO
New Member

I am getting events with
Time Event
4/2/19 3:15:34.000 AM Apr 02, 2019 3:15:34 AM xxxxxxxxx

I need to change event time format to YYYY-MM-DD HH:MM:SS,sss

0 Karma

vnravikumar
Champion
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...