Splunk Search

Date Format in required form

ncbshiva
Communicator

Hi i have a Date in the below form

201304
201306
201307

I want to convert to these to below form

APR-13
JUN-13
JUL-13

Please help me in this

Thanking you

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You can do that with a combination of strptime and strftime, see http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions for reference.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You can do that with a combination of strptime and strftime, see http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions for reference.

martin_mueller
SplunkTrust
SplunkTrust

Try this:

... | eval newdate = upper(strftime(strptime(date+"01", "%Y%m%d"), "%b-%y"))
0 Karma

ncbshiva
Communicator

i tried to convert using above functions, but didn,t work.
Please help me .

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...