Try this
.... | eval Time=strftime(strptime(date_hour.":".date_minute.":".date_second,"%H:%M:%S"),"%H:%M:%S) | ...
It should normalize Time to use 2-digit minute and second fields (hour, too). Then the events will sort properly.
Try this
.... | eval Time=strftime(strptime(date_hour.":".date_minute.":".date_second,"%H:%M:%S"),"%H:%M:%S) | ...
It should normalize Time to use 2-digit minute and second fields (hour, too). Then the events will sort properly.
|eval Time=strftime(_time, "%H:%M:%S") | eval Date=strftime(_time, "%A %F")
This works too
Thanks!
Thank you Rick!!! Do you also have the date cure too? So that days and months are in the proper chronological order.
Thanks again
Date is similar.
... | eval Date=strftime(strptime(date_wday." ".date_month."/".date_mday."/".date_year, "%a %m/%d/%Y"),"%a %m/%d/%Y") | ...
I suspect, however, there's a better way using _time to get the events in order. Depends on what you're trying to do.
agreed, I am sure there is a better way but this should get the answers I need today...
Thank you
....|eval Time=date_hour.":".date_minute.":".date_second | eval Date = date_wday." ".date_month."/".date_mday."/".date_year
|stats list(message_subject) as subj list(sender) as sender list(recipient) as recp list(file_name) as AttachmentName list(attachment_type) as AttachmentType list(vendor_action) as status values(Time) as Time values(Date) as Date by internal_message_id ....
This is a sample of the code I use to get the events with time and date...