Splunk Search

Need to remove T and Z from output timestamp

ravir_jbp
Explorer

I am trying to remove T and Z from the output timestamp results. Can you please help me with the query to remove  and space in the place of T and Z.

2023-11-01T15:54:00Z

Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| eval stime=strftime(strptime(stime,"%FT%TZ"),"%F %T")
| eval etime=strftime(strptime(etime,"%FT%TZ"),"%F %T")
| eval orgstime=strftime(strptime(orgstime,"%FT%TZ"),"%F %T")
| eval orgetime=strftime(strptime(orgetime,"%FT%TZ"),"%F %T")

View solution in original post

0 Karma

yuanliu
SplunkTrust
SplunkTrust

As I noted in https://community.splunk.com/t5/Splunk-Search/Date-time-formatting-variables-not-producing-result-I-..., the letter "Z" signifies a standard time zone and you should NOT simply remove it.  Instead, Splunk should process it as a timezone token before you render the end result in any string format you wanted.  In other words,

| eval stime=strftime(strptime(stime,"%FT%T%Z"),"%F %T")
| eval etime=strftime(strptime(etime,"%FT%T%Z"),"%F %T")
| eval orgstime=strftime(strptime(orgstime,"%FT%T%Z"),"%F %T")
| eval orgetime=strftime(strptime(orgetime,"%FT%T%Z"),"%F %T")

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| makeresults
| eval time="2023-11-01T15:54:00Z"
| eval reformatted=strftime(strptime(time,"%FT%TZ"),"%F %T")
0 Karma

ravir_jbp
Explorer

This is the final stats results I got it now. The query you have shared is used to modify specific time. But I like to modify the timestamp on all the below mentioned column. 

 

timestamp.JPG

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval stime=strftime(strptime(stime,"%FT%TZ"),"%F %T")
| eval etime=strftime(strptime(etime,"%FT%TZ"),"%F %T")
| eval orgstime=strftime(strptime(orgstime,"%FT%TZ"),"%F %T")
| eval orgetime=strftime(strptime(orgetime,"%FT%TZ"),"%F %T")
0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...