Splunk Search

Field Extraction Help

carmackd
Communicator

I would like to combine extracted values into a single field. Here is my transform

[end_time_extact]
REGEX = (\d+\/\d+\/\d+)[,](\d+:\d+:\d+)
FORMAT = end_time::$2

A comma seperates yy/mm/dd from hh:mm:ss and i would like to join the two into a single field.

Suggestions? I've tried

FORMAT = end_time::$1:$2

along with many other variations

Tags (1)
0 Karma

woodcock
Esteemed Legend

Do it in reverse order like this:

[end_time_extact]
REGEX = (\d+/\d+/\d+[,]\d+:\d+:\d+)
FORMAT = end_time::$1

[split_end_time]
SOURCE_KEY=end_time
REGEX = (?<end_time_part1>\d+/\d+/\d+)[,](?<end_time_part2>\d+:\d+:\d+)
0 Karma

dwaddle
SplunkTrust
SplunkTrust

can you supply a couple of sample (redacted if necessary) events?

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk &#43; Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...