Splunk Search

How to include "-" in between a field value?

Builder

I have a field lastrundate which has values 20190623 , 20190624 , 20190626.
I want to include an "-" in between them to make the value look like 2019-06-23 ,2019-06-24 ,2019-06-26.

I read the sed command does something similar.
Any inputs?

Thanks in Advance

0 Karma
1 Solution

Legend

Hi vrmandadi,
these values seems to be dates so you can use the date transforming functions, something like this:

| eval lastrundate=strftime(strptime(lastrundate,"%Y%m%d"),"%Y-%m-%d")

Bye.
Giuseppe

View solution in original post

Legend

Hi vrmandadi,
these values seems to be dates so you can use the date transforming functions, something like this:

| eval lastrundate=strftime(strptime(lastrundate,"%Y%m%d"),"%Y-%m-%d")

Bye.
Giuseppe

View solution in original post

Builder

Thank You that worked .Can you move this comment to the answer section.I will accept it

0 Karma