I'm new to the Splunk community. I'm trying to extract the date portion of this search result
M91040FA7104_Tue Jan 26 14:12:15 CST 2016
so everything after the _
. I have been banging on this for 4 hours and can't seem to get it to produce anything.
How about this
your base search | rex field=YourFieldName "_(?<YourDateField>\w+\s+\w+\s+\d+\s+\d+:\d+:\d+\s+\w+\s+\d+)$" | eval YourDateFieldInEpoch=strptime(YourDateField,"%a %b %d %H:%M:%S %Z %Y")
How about this
your base search | rex field=YourFieldName "_(?<YourDateField>\w+\s+\w+\s+\d+\s+\d+:\d+:\d+\s+\w+\s+\d+)$" | eval YourDateFieldInEpoch=strptime(YourDateField,"%a %b %d %H:%M:%S %Z %Y")