Splunk Search

Dashboard

kembgeorge
Loves-to-Learn

I have an issue when I try to convert my date time format to y/m/d/h/m it fails to do so 
I currently have my date time format example as 1629752225700

please can anyone help out 

0 Karma

ashvinpandey
Contributor

@kembgeorge Below are the two methods:

1. using convert command:

| convert ctime(<field_name>)


2. using eval:

| eval <field_name>=strftime(<field_name>,"%Y/%M/%d/%H/%M/%S")

Also, If this reply helps you, an upvote would be appreciated.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...