Hi @pm771 I think the Splunk docs are not very detailed about this and could be improved, for sure. I believe it's just python libraries in the Splunk backend so, yes, any valid python strftime() modifiers will work (dependent on the installed Splunk python version). Here's a run anywhere example I tried. | makeresults
| eval epoch=relative_time(_time, "@month")
,date1=strftime(relative_time(epoch, "@month"), "%Y-%m-%d")
,date2=strftime(relative_time(epoch, "@month"), "%Y-%m-%e")
,date3=strftime(relative_time(epoch, "@month"), "%Y-%-m-%-d")
,date4=strftime(relative_time(epoch, "@month"), "%Y-%#m-%#d") Note the %e has a leading whitespace so stick to either %-d or %#d. Hope this helps.
... View more