Splunk Search

Why does Splunk change date format from 2022-12-04 to 2022/12/04 when exporting to .csv?

CDel
Explorer

Hi All, 

I am unsure if this question has been answered already - I couldn't see it. 

I have a time field in Splunk that I have created using: 

| eval TimeStamp = strftime(_time, "%Y-%m-%d") 

In Splunk the format is correct, the problem I am having is when the search is exported to .csv the date format changes to "2022/12/04" from " 2022-12-04" when I need it to stay as the dashed version. The same thing happens when it runs via Splunk scheduler to create a .csv file. 

Any ideas on why or how to stop this? 

Thanks in advance, any help is appreciated! 

 

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

How are you exporting this? I just tried and it downloads to CSV as 2022-12-13.

I used the export button from the search results page

CDel
Explorer

@bowesmana  I’m using the export button as well, it does it wrong when the csv is created through a scheduled report too. 

I did try with a different character, so exporting it as ‘2022.12.04’ and that worked fine, it seems to be specifically the dashes my Splunk has a problem with? 

0 Karma

yuanliu
SplunkTrust
SplunkTrust

How are you reading the exported CSV?  Could it be a locale setting in that utility?

CDel
Explorer

I have been viewing the CSV in Excel - so I am thinking it is actually not a Splunk issue at all and an Excel one!

The data looks fine in Notepad. Off to post on Mr Excel next then I reckon. 😒

Thank you all for your help regardless - much appreciated. 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

That's strange - I wonder if it's a locale issue. There are a number of community posts recommending what you are doing.

What version of Splunk?

0 Karma

CDel
Explorer

It’s version 8.1.5 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

Happy CX Day, Splunk Community!

Happy CX Day, Splunk Community! CX stands for Customer Experience, and today, October 3rd, is CX Day — a ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...