Splunk Search

How do I prevent milliseconds from displaying in the _time field in search results?

Alexwii
New Member

Hello everyone !

I would like my search results to not display milliseconds in the _time field in the Search app, because it's useless for me. Example, I have 15:14:33:000 and I want 15:14:33.

Thank you so much for your answer.

alt text

0 Karma

renjith_nair
Legend

You can set the time to your favourite format

your search |eval _time=strftime(_time,"%d/%m/%Y %H:%M:%S")

You can set it permanent in props.conf if you don't care about millisecond precision in your searches
http://docs.splunk.com/Documentation/Splunk/6.3.2/Data/Configuretimestamprecognition

[<spec>]
TIME_FORMAT = %d/%m/%Y %H:%M:%S
Happy Splunking!
0 Karma

Alexwii
New Member

Thank you for your answer, but when I write your command, I have :

NaN/NaN/0NaN 
NaN:NaN:NaN.000

After personalize, it's same problem...

0 Karma

renjith_nair
Legend

Try your search|eval Time=strftime(_time,"%d/%m/%Y %H:%M:%S") |table Time , "other fields"

Happy Splunking!
0 Karma

Alexwii
New Member

Thanks you so much ! It's work !

But when I write in /opt/splunk/etc/apps/search/local/props.conf

[]

TIME_FORMAT = %d/%m/%Y %H:%M:%S

It's not work... I restart Splunk, wait +12h and it's not ok...

0 Karma

renjith_nair
Legend

Sorry you can ignore this part and remove this settings. This is for extracting the timestamp from your event(initially i thought so). Since your timestamp extraction is fine you don't need this.

Please see here :http://docs.splunk.com/Documentation/Splunk/6.3.2/Data/Configuretimestamprecognition#Reconfigure_how...

Happy Splunking!
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...