Splunk Search

How to to update hour of a timestamp variable?

mxh7777
Path Finder

Hi,

I'm looking for a way to change the hour of a time variable

Exemple :

myTime="2022-11-20 05:23:42"

and I want myTime to be equal "2022-11-20 08:00:00"

How can I proceed please ?


Thanks

Labels (1)
0 Karma

mxh7777
Path Finder

OK,

I think i get it.

This works

| eval myTime=strptime(strftime(strptime(myTime,"%Y-%m-%d %H:%M:%S") ,"%Y-%m-%d 08:%M:%S") ,"%Y-%m-%d %H:%M:%S")

but maybe there is a better way

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...