Splunk Search

How to change the date format from 'yyyy-mm-dd' to 'mm-dd-yyyy' on the saved search?

Neel88
Explorer

I am working on the saved search not index/lookup.

I tried this code - 

| eval date=strftime(strptime(<fieldname>,"%Y-%m-%d %H:%M:%S"), "%m-%d-%Y %H:%M:%S")

but getting the blank data. Pls help

 

Labels (7)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

There is nothing wrong with the eval statement, so it means that your field (which I assume is not the "<fieldname>" but the name of a field) is not in that format.

| makeresults
| eval x="2023-02-02 04:02:01"
| eval date=strftime(strptime(x,"%Y-%m-%d %H:%M:%S"), "%m-%d-%Y %H:%M:%S")
0 Karma

Neel88
Explorer

| loadjob savedsearch="nobody:splunk_fcr_evo:last_31_days_monitoring_data"
| eval New_date=strftime(strptime(Date,"%Y-%m-%d %H:%M:%S"), "%m-%d-%Y %H:%M:%S")
| fields Date, adt, FLOW, NB1, New_date

 

Above gives blank results in the New_date column

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Please show the value of the Date field after the loadjob

0 Karma

Neel88
Explorer

Neel88_0-1675326563955.png

Date

2022-06-04

2022-06-05

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

your Date is not in the same format as you are using on strptime. You haven’t have hours, minutes and seconds on it. For that reason this didn’t work. Just drop those away from format or use field which contains also those.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

Happy CX Day, Splunk Community!

Happy CX Day, Splunk Community! CX stands for Customer Experience, and today, October 3rd, is CX Day — a ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...