Splunk Search
Highlighted

formatting _time field into a YYYY-MM-DD field

Motivator

This search is ok
... | stats max(fieldname1) as fn1 by _time

but I want to control the format of the _time field to be format to be YYYY-MM-DD

How can I do this?

I know i can do ... | timechart span=d max(fieldname1) as fn1 but i am looking for another way as it relates to something I am working on and the timechart option won't work.

I am think something like

... | eval time_field=(_time,"YYYY-MM-DD")| stats max(fieldname1) as fn1 by time_field

Can this be done?

Tags (4)
0 Karma
Highlighted

Re: formatting _time field into a YYYY-MM-DD field

Motivator
0 Karma
Highlighted

Re: formatting _time field into a YYYY-MM-DD field

try this:
... | eval timefield=strptime
(
time,"%Y-%m-%d")|
stats max(fieldname1)
as fn1 by time_field

Highlighted

Re: formatting _time field into a YYYY-MM-DD field

Splunk Employee
Splunk Employee

Use convert:

... | convert timeformat="%Y-%m-%d" ctime(_time) AS ctime | ...

You can use whatever ... AS yourfield you want, of course.