Splunk Search

converting lastLogonTimestamp to readable date and time format in Splunk

samble
Path Finder

My ldap search for last logon (Active Directory) displays time in a format that makes it harder to read. How can I make the time to be represented as MM-DD-YYYY and XX:XX AM OR PM format? Below is a sample output. Thanks

lastLogonTimestamp: 2015-09-09T19:27:23.641679Z

0 Karma
1 Solution

somesoni2
Revered Legend

Assuming the lastLogonTimestamp is an extracted field, try this

..your base search | eval lastLogonTimestamp =strftime(strptime(lastLogonTimestamp,"%Y-%m-%dT%H:%M:%S.%QZ"),"%m-%d-%Y %H:%M %p")

Tested by this runanywhere search sample

| gentimes start=-1 |eval lastLogonTimestamp ="2015-09-09T19:27:23.641679Z" | eval lastLogonTimestamp =strftime(strptime(lastLogonTimestamp,"%Y-%m-%dT%H:%M:%S.%QZ"),"%m-%d-%Y %H:%M %p")

View solution in original post

somesoni2
Revered Legend

Assuming the lastLogonTimestamp is an extracted field, try this

..your base search | eval lastLogonTimestamp =strftime(strptime(lastLogonTimestamp,"%Y-%m-%dT%H:%M:%S.%QZ"),"%m-%d-%Y %H:%M %p")

Tested by this runanywhere search sample

| gentimes start=-1 |eval lastLogonTimestamp ="2015-09-09T19:27:23.641679Z" | eval lastLogonTimestamp =strftime(strptime(lastLogonTimestamp,"%Y-%m-%dT%H:%M:%S.%QZ"),"%m-%d-%Y %H:%M %p")

samble
Path Finder

Thanks for the timely response, it worked. The lastlogonTimestamp is an extracted field

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...