Hi knalla,
try this run everywhere search:
| makeresults
| eval myTimeString="Mon 07/23/2018 17:19:01.89", _time=strptime(myTimeString, "%a %m/%d/%Y %H:%M:%S.%2N"), epoch=_time
This will parse your string and creates _time
which will be shown human readable in Splunk, and epoch
as an epoch time. Read more about strptime()
here http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Commontimeformatvariables
Hope this helps ...
cheers, MuS
Hi knalla,
try this run everywhere search:
| makeresults
| eval myTimeString="Mon 07/23/2018 17:19:01.89", _time=strptime(myTimeString, "%a %m/%d/%Y %H:%M:%S.%2N"), epoch=_time
This will parse your string and creates _time
which will be shown human readable in Splunk, and epoch
as an epoch time. Read more about strptime()
here http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Commontimeformatvariables
Hope this helps ...
cheers, MuS