Hello splunk lovers!i want help with date field and i want fast.
i have field, format example: data_started 01.01.2016 0:00:00 AND i want to take from field date_started only year, like 2016.please help!
Hi @splunk_enjoyer,
please try
| eval year=straftime(data_started,"%Y")
or
| rex field=data_started "^\d+\.\d+\.(?<year>\d+)
Ciao.
Giuseppe