Splunk Search

formatting _time field into a YYYY-MM-DD field

HattrickNZ
Motivator

This search is ok
... | stats max(fieldname1) as fn1 by _time

but I want to control the format of the _time field to be format to be YYYY-MM-DD

How can I do this?

I know i can do ... | timechart span=d max(fieldname1) as fn1 but i am looking for another way as it relates to something I am working on and the timechart option won't work.

I am think something like

... | eval time_field=(_time,"YYYY-MM-DD")| stats max(fieldname1) as fn1 by time_field

Can this be done?

Tags (4)
0 Karma

jtrucks
Splunk Employee
Splunk Employee

Use convert:

... | convert timeformat="%Y-%m-%d" ctime(_time) AS ctime | ...

You can use whatever ... AS yourfield you want, of course.

--
Jesse Trucks
Minister of Magic

stephane_cyrill
Builder

try this:
... | eval time_field=strptime
(_time,"%Y-%m-%d")|
stats max(fieldname1)
as fn1 by time_field

HattrickNZ
Motivator
0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...