We are using a lookuptable with CSV's for reports. However, the
_time field has the following format for time:
How do I get Splunk to interpret that for
Is there a way to edit the
_time field to get rid of everything from the "T" on and show 2015-06-10 and use strptime?
This time can be parsed by
strptime without any changes. For example
|makeresults | eval time = "2015-06-10T20:04:51.254843Z" | eval parsedTime = strptime(time, "%Y-%m-%dT%H:%M:%S.%6QZ")
It works somewhat, but the
eval of 2015-06-10T20:04:51.254843Z converts the time to:
The time should be June 10, 2015.
I'm trying to get Spunk to interpret the format of our time field " 2015-06-10T20:04:51.254843Z" to make a time graph.
you need to assign _time to the lookup time value.
| inputlookup REPORT.csv | eval time=strptime(lastLogonTimestamp,"%m/%d/%y")
The above seemed to work.