Splunk Search

How to to update hour of a timestamp variable?

Path Finder


I'm looking for a way to change the hour of a time variable

Exemple :

myTime="2022-11-20 05:23:42"

and I want myTime to be equal "2022-11-20 08:00:00"

How can I proceed please ?


Labels (2)
0 Karma

Path Finder


I think i get it.

This works

| eval myTime=strptime(strftime(strptime(myTime,"%Y-%m-%d %H:%M:%S") ,"%Y-%m-%d 08:%M:%S") ,"%Y-%m-%d %H:%M:%S")

but maybe there is a better way

0 Karma
Get Updates on the Splunk Community!

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...

Starting With Observability: OpenTelemetry Best Practices

Tech Talk Starting With Observability: OpenTelemetry Best Practices Tuesday, October 17, 2023   |  11AM PST / ...

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW! Every day the list of sources Admins are responsible for gets bigger and bigger, often making ...