Splunk Search

strftime day and month: Splunk vs Python

pm771
Communicator

My question is about day and month components of a date without leading zeroes.

Python docs provide %-d and %-m respectively.

Splunk docs do not show these options.  Splunk, however, has %e which seems to be the same as %-d.  I did not find any option for decimal month number.

I have tried and Splunk seems to accept %-d and %-m

Is it standard feature that I can rely on? Is it implementation dependent?

Did I miss something in Splunk docs?

Tags (2)
0 Karma

yeahnah
Motivator

Hi @pm771 

I think the Splunk docs are not very detailed about this and could be improved, for sure.  I believe it's just python libraries in the Splunk backend so, yes, any valid python strftime() modifiers will work (dependent on the installed Splunk python version).

Here's a run anywhere example I tried.

 

| makeresults
| eval epoch=relative_time(_time, "@month")
      ,date1=strftime(relative_time(epoch, "@month"), "%Y-%m-%d")
      ,date2=strftime(relative_time(epoch, "@month"), "%Y-%m-%e")
      ,date3=strftime(relative_time(epoch, "@month"), "%Y-%-m-%-d")
      ,date4=strftime(relative_time(epoch, "@month"), "%Y-%#m-%#d")

 


Note the %e has a leading whitespace so stick to either %-d or %#d.

Hope this helps.

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...