Based on what I can understand, you can try using something like this and tweak it as needed. | makeresults
| eval datetime_str="Thu 10 Oct 2024 08:48:12:574 EDT"
| eval datetime=strptime(datetime_str, "%a %d %b %Y %H:%M:%S:%3N %Z")
| eval day_name=strftime(datetime, "%A"),
day_of_month=strftime(datetime, "%d"),
month=strftime(datetime, "%b"),
year=strftime(datetime, "%Y"),
week_number=strftime(datetime, "%U"),
time_part=strftime(datetime, "%H:%M:%S")
| fields datetime_str, datetime, day_name, day_of_month, month, year, week_number, time_part
| eval hour=substr(time_part, 1, 2),
minute=substr(time_part, 4, 2),
second=substr(time_part, 7, 2)
... View more