Afternoon,
I'm trying to format the date field for the malware data model. Converting it from epoc. But I dont know what format is wants I've guessed a bunch of different formats but it says they are unexpected.
"unexpected values"
| convert ctime(date) timeformat="%Y-%m-%dT%H:%M:%S"
| convert ctime(date) timeformat=" WHAT FORMAT SHOULD THIS BE?"
Your timeformat is correct, testing an epoc date works fine.
| makeresults | eval date="1623216888"
| convert ctime(date) as new_date timeformat="%Y-%m-%dT%H:%M:%S"
| table new_date
Did you check your date fiels is the right epoc format?
-----
An upvote would be appreciated if it helps!