Splunk Search

How to expand the dates between two dates?

Sankar_g30
Loves-to-Learn

I want to display the date between two date range EX. 3/11 -3/19

Field : SDate= 3/11/2018 EDate=3/19/2018

I need the output as 3/11 , 3/12, 3/13.....3/19.

Tags (1)
0 Karma

javiergn
Super Champion

@Sankar_g30 please do not forget to accept an answer if you are happy with it

0 Karma

mayurr98
Super Champion

hey try this run anywhere search

| makeresults 
| eval SDate="3/11/2018",EDate="3/19/2018" 
| rex field=SDate "(?<sdate>\d+\/\d+)" 
| rex field=EDate "(?<edate>\d+\/\d+)"

In your environment, you should write

<your_base_Search> | rex field=SDate "(?<sdate>\d+\/\d+)" | rex field=EDate "(?<edate>\d+\/\d+)"

let me know if this helps!

0 Karma

javiergn
Super Champion

Hi,

Use gentimes for that:

| gentimes start=3/11/2018 end=3/19/2018 increment=1d
| eval dates = strftime(starttime, "%m/%d")
| table dates

Output:

alt text

If you want to get rid of the leading zeros I can show you how to do that too.

Regards,
J

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...