Hi All,
I am unsure if this question has been answered already - I couldn't see it.
I have a time field in Splunk that I have created using:
| eval TimeStamp = strftime(_time, "%Y-%m-%d")
In Splunk the format is correct, the problem I am having is when the search is exported to .csv the date format changes to "2022/12/04" from " 2022-12-04" when I need it to stay as the dashed version. The same thing happens when it runs via Splunk scheduler to create a .csv file.
Any ideas on why or how to stop this?
Thanks in advance, any help is appreciated!
How are you exporting this? I just tried and it downloads to CSV as 2022-12-13.
I used the export button from the search results page
@bowesmana I’m using the export button as well, it does it wrong when the csv is created through a scheduled report too.
I did try with a different character, so exporting it as ‘2022.12.04’ and that worked fine, it seems to be specifically the dashes my Splunk has a problem with?
How are you reading the exported CSV? Could it be a locale setting in that utility?
I have been viewing the CSV in Excel - so I am thinking it is actually not a Splunk issue at all and an Excel one!
The data looks fine in Notepad. Off to post on Mr Excel next then I reckon. 😒
Thank you all for your help regardless - much appreciated.
That's strange - I wonder if it's a locale issue. There are a number of community posts recommending what you are doing.
What version of Splunk?
It’s version 8.1.5