Splunk Search

How to change time format in my search?

Explorer

I am using search
...|timechart sum(x) by y
but _time is showing as 2014-4-3-T 00:00, but I want the format of _time on the x axis to be 2014-4-3 only. How do I do this?

0 Karma
1 Solution

Builder

use this

..|timechart sum(x) by y|eval _time=strftime(_time,"%Y"-%m-%d)

View solution in original post

Builder

use this

..|timechart sum(x) by y|eval _time=strftime(_time,"%Y"-%m-%d)

View solution in original post

Explorer

Thanks its working...

0 Karma