Splunk Search

How do I add the time zone after the time in the field?

Veeru
Path Finder

Hello,
Good Day!

I having the values in the field Data As shown below

2022-05-31 10:18:09   emea  
2022-05-31
2022-05-31 10:18:14    apac 
2022-05-31
2022-05-31 10:18:20     us 

I want to show the time zone as well like if emea comes after time it should show CST
Output should be as follows:

2022-05-31 10:18:09 CST  emea  
2022-05-31
2022-05-31 10:18:14 HKT   apac 
2022-05-31
2022-05-31 10:18:20  EDT   us 

Please help me on this
Thank you in Advance
Veeru

Labels (2)
Tags (1)
0 Karma

Veeru
Path Finder

Thanks for the help i got the results

0 Karma

venky1544
Builder

Hi @Veeru 

if it resolved your issue can you please accept the solution it might help others in the group

 

note:- If it helps karma is appreciated/if it resolves acceptance as solution is appreciated 

0 Karma

venky1544
Builder

hi @Veeru 

you can try the below query 

|makeresults |eval new = "2022-05-31 10:18:09 emea"
|append [|makeresults |eval new= "2022-05-31 10:18:14 apac"]
|append [|makeresults |eval new= "2022-05-31 10:18:20 us "]
|eval new=replace(new,"emea", "CST emea")
|eval new=replace(new,"apac", "HKT apac")
|eval new=replace(new,"us", "EDT us")

 

If it helps karma is appreciated/if it resolves acceptance as solution is appreciated 

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...