Splunk Search

Eval Expression in Data Model

ebs
Communicator

Hi,

I'm trying to create an eval expression in my data model which is based on _time. Can you please advise on what I'm doing wrong?

0 Karma
1 Solution

kamlesh_vaghela
SplunkTrust
SplunkTrust

My bad just put <<YOUR_CODE>> and try

 

strftime(_time,"%Y-%m-%d")

View solution in original post

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

remove | eval from eval block. just date=<<YOUR_CODE>>

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

My bad just put <<YOUR_CODE>> and try

 

strftime(_time,"%Y-%m-%d")

0 Karma

ebs
Communicator

I get this error

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...