Splunk Search

Date extraction command Question for LDAP dump

daryllj
Path Finder

hi there- I tried a few things already, but looking to get guidence on this one- I am using the LDAP query module in Splunk to dump out directory information and then present into a simple table, and running into a challenge simplifying extraction of the date from the AD account creation field:

| ldapsearch basedn="XXXXXXXXXXX" search="(&(objectCategory=user)(objectClass=user)(distinguishedName=*))" attrs="displayName,distinguishedName,mail,lastLogonTimestamp,whenCreated" 

I want to simplify presentation of the two date and time fields:  lasLogonTimestamp and whenCreated.

What I get with these fields today when I output to a table (example)

2019-05-06 16:53:24+00:00

What I want to see:

2019-05-06

What I have tried:

adding in:

| eval Created=strftime(whenCreated,"%Y%m%d") | prior to my table command.

this seems to result in nothing being populated in the new field (I am expecting just a date value) ...I am not sure if the strftime command is correct when it comes to this format of data...

thoughts welcomed as always

 

 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

To convert a timestamp from one string format into another string format you must first convert it into an integer using strptime.

| eval Created=strftime(strptime(whenCreated,"%Y-%m-%d %H:%M:%S%:z"),"%Y-%m-%d") | 
---
If this reply helps you, Karma would be appreciated.

View solution in original post

daryllj
Path Finder

Thanks for taking the time out to educate me on this one- works perfectly,  I really appreciate you taking a few minutes of your time!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

To convert a timestamp from one string format into another string format you must first convert it into an integer using strptime.

| eval Created=strftime(strptime(whenCreated,"%Y-%m-%d %H:%M:%S%:z"),"%Y-%m-%d") | 
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...