Splunk Search

Time Format

vaibhavbeohar
Path Finder

Hi I have a file with fields CloseDateTime and StartDateTime, both the field have a format like "2013-03-08 16:26 PM", I would like to have a separate field which will convert this format into single digit month and would require another field with date of the month.

Thanks.

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

The most robust approach would likely be to strptime your source fields and then to strftime them into whatever you like.

See docs on both here: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...