Hi, I am currently attempting to split the Date and Time from one field into 2 or more fields. I have read some of the questions and answers here, but to no avail. I am working with Starbucks.csv, which shows the Date, Volume and Closing stock price of Starbucks. The Date format is in YYYY-MM-DD. My intention is to split the Date to Year, Month and Day Fields respectively. I have seen some of the community answers and many proposed a simple method such as |eval YearNo=(Date, "%Y) for the Year field. However, I tried and the search simply did not return any new field, Below is a snippet of the attempt. I put Date and YearNo in the same table to show how YearNo was not extracted. My next thought was that maybe splunk did not register the Date field as a date but merely as a string. I went ahead and plotted the Date vs Volume Chart on the visualization option and it does seem that Splunk registered the Date as date, and hence the plot was crafted nicely. The snippet is shown below. I would greatly appreciate if someone could enlighten me on this situation and how can I extract the date to their individual fields. Cheers, Lucas
... View more