Splunk Search

formatting _time field into a YYYY-MM-DD field

HattrickNZ
Motivator

This search is ok
... | stats max(fieldname1) as fn1 by _time

but I want to control the format of the _time field to be format to be YYYY-MM-DD

How can I do this?

I know i can do ... | timechart span=d max(fieldname1) as fn1 but i am looking for another way as it relates to something I am working on and the timechart option won't work.

I am think something like

... | eval time_field=(_time,"YYYY-MM-DD")| stats max(fieldname1) as fn1 by time_field

Can this be done?

Tags (4)
0 Karma

jtrucks
Splunk Employee
Splunk Employee

Use convert:

... | convert timeformat="%Y-%m-%d" ctime(_time) AS ctime | ...

You can use whatever ... AS yourfield you want, of course.

--
Jesse Trucks
Minister of Magic

stephane_cyrill
Builder

try this:
... | eval time_field=strptime
(_time,"%Y-%m-%d")|
stats max(fieldname1)
as fn1 by time_field

HattrickNZ
Motivator
0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...