Splunk Search

TIme Conversion

krvamsireddy
Explorer

Hi ,

how to change the below raw time field to yyyy-mm-dd hh:mm:ss

2020-09-09T18:21:12.2685607Z

am using the below query and didnt get any result 

eval time = strftime(activityDateTime,"%Y-%m-%d %H:%M:%S")

Can someone please help

Labels (1)
0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust

@krvamsireddy 

check updated answer.

————————————
If this helps, give a like below.

View solution in original post

thambisetty
SplunkTrust
SplunkTrust

strftime is used to convert unix timestamp to human readable format.

you should use strptime to convert time which is already in human readable format if you need to format it.

| makeresults | eval activityDateTime="2020-09-09T18:21:12.2685607Z"
| eval time = strftime(strptime(activityDateTime,"%Y-%m-%dT%H:%M:%S"),"%Y-%m-%d %H:%M:%S")
————————————
If this helps, give a like below.
0 Karma

krvamsireddy
Explorer

 

krvamsireddy_2-1599812787173.png

 

still in the old format, and time column is still blank 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What do you mean by raw time field? What fields do you have? Do you get anything in the time field you created?

0 Karma

krvamsireddy
Explorer

No i didnt get anything.

raw time field - time format which i get in the event 

activityDateTIme

krvamsireddy_0-1599812918849.png

 

0 Karma

thambisetty
SplunkTrust
SplunkTrust

@krvamsireddy 

check updated answer.

————————————
If this helps, give a like below.

ITWhisperer
SplunkTrust
SplunkTrust

Looks like you need to parse the activityDateTime with strptime and then format that with strftime

 

eval time = strptime(strptime(activityDateTime, "%Y-%m-%dT%H:%M:%S.%Q"),"%Y-%m-%d %H:%M:%S")

Or you could just parse the activityDateTime string into an epoch time and the use fieldformat on the time field for display purposes

 

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...