Splunk Search

Date Format in required form

ncbshiva
Communicator

Hi i have a Date in the below form

201304
201306
201307

I want to convert to these to below form

APR-13
JUN-13
JUL-13

Please help me in this

Thanking you

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You can do that with a combination of strptime and strftime, see http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions for reference.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You can do that with a combination of strptime and strftime, see http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions for reference.

martin_mueller
SplunkTrust
SplunkTrust

Try this:

... | eval newdate = upper(strftime(strptime(date+"01", "%Y%m%d"), "%b-%y"))
0 Karma

ncbshiva
Communicator

i tried to convert using above functions, but didn,t work.
Please help me .

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...