Hi All,
I am unsure if this question has been answered already - I couldn't see it.
I have a time field in Splunk that I have created using:
| eval TimeStamp = strftime(_time, "%Y-%m-%d")
In Splunk the format is correct, the problem I am having is when the search is exported to .csv the date format changes to "2022/12/04" from " 2022-12-04" when I need it to stay as the dashed version. The same thing happens when it runs via Splunk scheduler to create a .csv file.
Any ideas on why or how to stop this?
Thanks in advance, any help is appreciated!
... View more