Hello,
i want to nicely display the date + time of the first and last event on a dashboard.
for this i used:
head 1 | table _time
tail 1 | table _time
if i format it as single value it's not displayed nice on the dashboard. Is there a trick available to display it nicely on the dashboard as single value (i do not want to display it in a table)
thx a lot
matthias
Hi,
I believe you can change the time format using either,
convert ctime(fieldname),
http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Convert
or
fieldformat "fieldname"=strftime('fieldname', "%c")
http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Fieldformat
Hope this helps
Derek