Don't forget the "%Z" in the
strptime format string to pick up the time zone. Also, use "%y" for two-digit year.
You can also combine these commands into a single eval:
| eval SystemTime=strftime(strptime(SystemTime, "%Y-%m-%dT%H:%M:%S.%9Q%Z"), "%y-%m-%d %H:%M")
but i have forgotten to say this field which exact name is "TimeCreated SystemTime" is in an xml log
so how to extract this specific field and to format it in the same time please??
A copy-and-paste sample of the log is easier to work with than an image.
rex command to extract the time field:
`... | rex "SystemTime='(?<SystemTime>[^']+)" | ...`