Splunk Search

Why does Splunk change date format from 2022-12-04 to 2022/12/04 when exporting to .csv?

CDel
Explorer

Hi All, 

I am unsure if this question has been answered already - I couldn't see it. 

I have a time field in Splunk that I have created using: 

| eval TimeStamp = strftime(_time, "%Y-%m-%d") 

In Splunk the format is correct, the problem I am having is when the search is exported to .csv the date format changes to "2022/12/04" from " 2022-12-04" when I need it to stay as the dashed version. The same thing happens when it runs via Splunk scheduler to create a .csv file. 

Any ideas on why or how to stop this? 

Thanks in advance, any help is appreciated! 

 

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

How are you exporting this? I just tried and it downloads to CSV as 2022-12-13.

I used the export button from the search results page

CDel
Explorer

@bowesmana  I’m using the export button as well, it does it wrong when the csv is created through a scheduled report too. 

I did try with a different character, so exporting it as ‘2022.12.04’ and that worked fine, it seems to be specifically the dashes my Splunk has a problem with? 

0 Karma

yuanliu
SplunkTrust
SplunkTrust

How are you reading the exported CSV?  Could it be a locale setting in that utility?

CDel
Explorer

I have been viewing the CSV in Excel - so I am thinking it is actually not a Splunk issue at all and an Excel one!

The data looks fine in Notepad. Off to post on Mr Excel next then I reckon. 😒

Thank you all for your help regardless - much appreciated. 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

That's strange - I wonder if it's a locale issue. There are a number of community posts recommending what you are doing.

What version of Splunk?

0 Karma

CDel
Explorer

It’s version 8.1.5 

0 Karma
Get Updates on the Splunk Community!

There's No Place Like Chrome and the Splunk Platform

Watch On DemandMalware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

The Great Resilience Quest: 5th Leaderboard Update

The fifth leaderboard update for The Great Resilience Quest is out >> 🏆 Check out the ...

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...