Splunk Search

Date Format in required form

ncbshiva
Communicator

Hi i have a Date in the below form

201304
201306
201307

I want to convert to these to below form

APR-13
JUN-13
JUL-13

Please help me in this

Thanking you

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You can do that with a combination of strptime and strftime, see http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions for reference.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You can do that with a combination of strptime and strftime, see http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions for reference.

martin_mueller
SplunkTrust
SplunkTrust

Try this:

... | eval newdate = upper(strftime(strptime(date+"01", "%Y%m%d"), "%b-%y"))
0 Karma

ncbshiva
Communicator

i tried to convert using above functions, but didn,t work.
Please help me .

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...