Splunk Search

listing _time changes the format to epoch

frbuser
Path Finder

It looks like using stats list(_time) displays the results in epoch. How do I make this more human readable?

0 Karma
1 Solution

vnravikumar
Champion

Hi @frbuser

Please try

|eval date = strftime(_time,"%d-%m-%Y")| stats list(date)

View solution in original post

0 Karma

vnravikumar
Champion

Hi @frbuser

Please try

|eval date = strftime(_time,"%d-%m-%Y")| stats list(date)

View solution in original post

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.