- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
jagadeeshm
Contributor
02-07-2018
04:04 AM
Here is my SPL -
| gentimes start=02/07/2017 end=02/08/2017 increment=1h
| convert timeformat="%Y-%m-%d %H:%M:%S" ctime(starttime) as _time
| fields _time
| eval HourOfDay=strftime(_time, "%H")
| eval BucketMinuteOfHour=strftime(_time, "%M")
Why is this not generating HourOfDay and BucketMinuteOfHour fields in the results?
Thanks!
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

kamlesh_vaghela

SplunkTrust
02-07-2018
04:15 AM
HI @jagadeeshm,
Can you please try below two searches?
I don't know why you format the time but below is working for me. Only value of increment parameter is different. Please check it nad see the difference.
| gentimes start=02/07/2017 end=02/08/2017 increment=1m
| rename starttime as _time
| fields _time
| eval HourOfDay=strftime(_time, "%H")
| eval BucketMinuteOfHour=strftime(_time, "%M")
AND
| gentimes start=02/07/2017 end=02/08/2017 increment=1s
| rename starttime as _time
| fields _time
| eval HourOfDay=strftime(_time, "%H")
| eval BucketMinuteOfHour=strftime(_time, "%M")
Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

kamlesh_vaghela

SplunkTrust
02-07-2018
04:15 AM
HI @jagadeeshm,
Can you please try below two searches?
I don't know why you format the time but below is working for me. Only value of increment parameter is different. Please check it nad see the difference.
| gentimes start=02/07/2017 end=02/08/2017 increment=1m
| rename starttime as _time
| fields _time
| eval HourOfDay=strftime(_time, "%H")
| eval BucketMinuteOfHour=strftime(_time, "%M")
AND
| gentimes start=02/07/2017 end=02/08/2017 increment=1s
| rename starttime as _time
| fields _time
| eval HourOfDay=strftime(_time, "%H")
| eval BucketMinuteOfHour=strftime(_time, "%M")
Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
jagadeeshm
Contributor
02-07-2018
04:20 AM
Thanks! It works for most part, but I don't see the seconds in the time.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
jagadeeshm
Contributor
02-07-2018
04:22 AM
Ok, If I use ctime later it works -
| gentimes start=02/07/2017 end=02/08/2017 increment=1h
| rename starttime as _time
| fields _time
| eval HourOfDay=strftime(_time, "%H")
| eval BucketMinuteOfHour=strftime(_time, "%M")
| convert timeformat="%Y-%m-%d %H:%M:%S" ctime(_time) as _time
Intersting!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

kamlesh_vaghela

SplunkTrust
02-07-2018
04:27 AM
Yeah..
Your issue resolved?
