I have this data:
Splunk is reading this timestamp as:
I do NOT want to capture the hundredths of a second, as this is supposed to be a new field. Each field is separated by a ',' (comma).
So, this is what I'm looking for:
Anything helps! Thanks.
| makeresults | eval timestampfield = "4/8/19 6:01:47.200 PM" | eval timestampfield= strptime(timestampfield, "%m/%d/%y %I:%M:%S.%3Q %p") | fieldformat timestampfield = strftime(timestamp_field, "%d/%m/%Y %H:%M:%S")