- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
jagadeeshm
Contributor
02-07-2018
04:04 AM
Here is my SPL -
| gentimes start=02/07/2017 end=02/08/2017 increment=1h
| convert timeformat="%Y-%m-%d %H:%M:%S" ctime(starttime) as _time
| fields _time
| eval HourOfDay=strftime(_time, "%H")
| eval BucketMinuteOfHour=strftime(_time, "%M")
Why is this not generating HourOfDay and BucketMinuteOfHour fields in the results?
Thanks!
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/de369/de36955662072a2b0e69a9b2caf31b826d7a55e8" alt="kamlesh_vaghela kamlesh_vaghela"
kamlesh_vaghela
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
SplunkTrust
02-07-2018
04:15 AM
HI @jagadeeshm,
Can you please try below two searches?
I don't know why you format the time but below is working for me. Only value of increment parameter is different. Please check it nad see the difference.
| gentimes start=02/07/2017 end=02/08/2017 increment=1m
| rename starttime as _time
| fields _time
| eval HourOfDay=strftime(_time, "%H")
| eval BucketMinuteOfHour=strftime(_time, "%M")
AND
| gentimes start=02/07/2017 end=02/08/2017 increment=1s
| rename starttime as _time
| fields _time
| eval HourOfDay=strftime(_time, "%H")
| eval BucketMinuteOfHour=strftime(_time, "%M")
Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/de369/de36955662072a2b0e69a9b2caf31b826d7a55e8" alt="kamlesh_vaghela kamlesh_vaghela"
kamlesh_vaghela
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
SplunkTrust
02-07-2018
04:15 AM
HI @jagadeeshm,
Can you please try below two searches?
I don't know why you format the time but below is working for me. Only value of increment parameter is different. Please check it nad see the difference.
| gentimes start=02/07/2017 end=02/08/2017 increment=1m
| rename starttime as _time
| fields _time
| eval HourOfDay=strftime(_time, "%H")
| eval BucketMinuteOfHour=strftime(_time, "%M")
AND
| gentimes start=02/07/2017 end=02/08/2017 increment=1s
| rename starttime as _time
| fields _time
| eval HourOfDay=strftime(_time, "%H")
| eval BucketMinuteOfHour=strftime(_time, "%M")
Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
jagadeeshm
Contributor
02-07-2018
04:20 AM
Thanks! It works for most part, but I don't see the seconds in the time.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
jagadeeshm
Contributor
02-07-2018
04:22 AM
Ok, If I use ctime later it works -
| gentimes start=02/07/2017 end=02/08/2017 increment=1h
| rename starttime as _time
| fields _time
| eval HourOfDay=strftime(_time, "%H")
| eval BucketMinuteOfHour=strftime(_time, "%M")
| convert timeformat="%Y-%m-%d %H:%M:%S" ctime(_time) as _time
Intersting!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/de369/de36955662072a2b0e69a9b2caf31b826d7a55e8" alt="kamlesh_vaghela kamlesh_vaghela"
kamlesh_vaghela
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
SplunkTrust
02-07-2018
04:27 AM
Yeah..
Your issue resolved?
data:image/s3,"s3://crabby-images/1a552/1a552ff33d37f94e7c5bc13132edaa973c529815" alt=""