Splunk Search

Date getting null values on StrpTime?

iupreti
Explorer

Screenshot 2022-12-05 at 6.45.50 AM.png
I've field name opened_at with the date value shown in the image. But, while taking value from it, it returns a null value. Am I missing something here?

Labels (2)
0 Karma
1 Solution

yuanliu
SplunkTrust
SplunkTrust

The date format appears to be "%d/%m/%Y", not "%m/%d/%Y".

View solution in original post

yuanliu
SplunkTrust
SplunkTrust

The date format appears to be "%d/%m/%Y", not "%m/%d/%Y".

iupreti
Explorer

Screenshot 2022-12-05 at 7.47.40 AM.png
Tried that as well but no luck

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @iupreti

you need to remove quotes for opened_at inside strptime function.

can you try runing removing quotes,

It should work

iupreti
Explorer

@SanjayReddyThank you it worked.

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...