Splunk Search

change time on date field

_Mauro_Costa_
Explorer

Hello,
I have 2 columns, one with date and other with the day of week
based on day of week whenever is Saturday or Sunday, I want to change the time to 9 am
How can I do this?

submitteddayweekresult
13/03/2025 14:24Thursday13/03/2025 14:24
12/03/2025 09:31Wednesday12/03/2025 09:31
11/03/2025 13:45Tuesday11/03/2025 13:45
10/03/2025 18:11Monday10/03/2025 18:11
09/03/2025 11:21Sunday09/03/2025 09:00
08/03/2025 21:55Saturday08/03/2025 09:00
07/03/2025 10:24Friday07/03/2025 10:24
Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @_Mauro_Costa_ ,

you could try with:

| eval date=if(dayweek IN (Saturday,Sunday),strftime(strptime(date,"%d/%m/%Y %H:%M"),"%d/%m/%Y 9.00"), date)

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @_Mauro_Costa_ ,

you could try with:

| eval date=if(dayweek IN (Saturday,Sunday),strftime(strptime(date,"%d/%m/%Y %H:%M"),"%d/%m/%Y 9.00"), date)

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...