Splunk Search

Search and Extract date from string

Laxman24
Explorer

Hi All,

I need some help in searching,

I have the following data : 

Field1Field2
2021-05-14X03:02:57YXa
2021-05-13X05:12:13YXb
2021-05-16X04:06:45YXc

 

So, I'd like to make a search that using the current date, assuming that today is 2021-05-16, 

if I run the search it shows the output

2021-05-16X04:06:45YXc

 

so if the next day I run the search again, it will only return the 2021-05-17 data

Could someone help me on this?

Thank you so much!

Labels (4)
0 Karma
1 Solution

kamlesh_vaghela
SplunkTrust
SplunkTrust

@Laxman24 

Can you please try this?

 

YOUR_SEARCH
| where (strftime(now(),"%Y-%m-%d")=substr(Field1,0,10))

 

 

My Sample Search :

 

| makeresults |eval _raw="Field1	Field2
2021-05-14X03:02:57Y	Xa
2021-05-13X05:12:13Y	Xb
2021-06-07X04:06:45Y	Xc" | multikv forceheader=1
| where (strftime(now(),"%Y-%m-%d")=substr(Field1,0,10))

 


 Thanks
KV
▄︻̷̿┻̿═━一

If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.

View solution in original post

kamlesh_vaghela
SplunkTrust
SplunkTrust

@Laxman24 

Can you please try this?

 

YOUR_SEARCH
| where (strftime(now(),"%Y-%m-%d")=substr(Field1,0,10))

 

 

My Sample Search :

 

| makeresults |eval _raw="Field1	Field2
2021-05-14X03:02:57Y	Xa
2021-05-13X05:12:13Y	Xb
2021-06-07X04:06:45Y	Xc" | multikv forceheader=1
| where (strftime(now(),"%Y-%m-%d")=substr(Field1,0,10))

 


 Thanks
KV
▄︻̷̿┻̿═━一

If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.

Laxman24
Explorer

Thanks @kamlesh_vaghela  !!

 

it seems worked! Thank you!!!

0 Karma
Get Updates on the Splunk Community!

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...