I have a date field "Expiry" that comes in this lovely format:
To: Thursday, 17 July 2036 00:59:59 o'clock BST
I could work out an epoch date easily from e.g.
17/07/2036 00:59:59 using
eval Expiry_Epoch=strptime(Expiry, "%d/%m/%y %H:%M:%s")
but %m only recognises a numerical, not an alphabetical month.
Does anyone know how I can recognise an alphabetical month like "July"?
Thank
Try this
| eval Expiry_Epoch=strptime(Expiry, "%A, %d %B %Y %H:%M:%S o'clock %Z")
you can use %B
See specifying months section here http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Commontimeformatvariables