Splunk Search

how to display time of event as a table column

seanlon11
Path Finder

I have the following query:

host=wps03 mc_getLDAPGroupsTimer | table time host username mc_getLDAPGroupsTimer | sort -mc_getLDAPGroupsTimer

I am trying to get the date and time to display in the table, so I can see what happened when, but I obviously have the syntax incorrect. Or, maybe this is not possible for some logical reason.

How can I display the date and time of an event in a table?

Thanks, Sean

Tags (1)
1 Solution

southeringtonp
Motivator

You have the right idea, but you appear to be missing the underscore at the beginning of the _time field.

View solution in original post

southeringtonp
Motivator

You have the right idea, but you appear to be missing the underscore at the beginning of the _time field.

seanlon11
Path Finder

Awesome, worked like a charm!

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...