I currently have 3 different fields that contain parts of a date that must be put together to give a full time. I have day, hour and minute fields that are currently separate and need to be combined as I want to display the time an event occurred in a table.
1. Field 1 = day
2. Field 2 = hour
3. Field 3 = minute
I need it to be:
1. Field 1 = day:hour:minute
If someone could help with this it would be much appreciated.
HI asewell97,
are youspeking of search time or index time? in other words: did you already indexed data and you want to display date field or you want to index events setting the correct timestamp using the three fields?
If you're working at search time, it's easy, use eval command in your searches:
| eval my_date=field1." ".field2.":".field3
If instead you are speaking of index time, please share an example of your logs to create the correct TIME_FORMAT option.
Ciao.
Giuseppe
HI asewell97,
are youspeking of search time or index time? in other words: did you already indexed data and you want to display date field or you want to index events setting the correct timestamp using the three fields?
If you're working at search time, it's easy, use eval command in your searches:
| eval my_date=field1." ".field2.":".field3
If instead you are speaking of index time, please share an example of your logs to create the correct TIME_FORMAT option.
Ciao.
Giuseppe
Hi, the eval command was what I was looking for. I've got it all working now so thanks for the help.
Use concatenation.
... | eval field=field1.":".field2.":"field3