Why is time formatting not working with the following search:
index=_internal sourcetype=splunkd "Ignoring" AND "binary" | eval time=strftime(_time, "%m/%d/%y %H:%M:%S") | stats earliest(_time) as start, latest(_time) as stop by message, host
The field name created for formatted _time is not used in stats, hence the problem. Try like this
index=_internal sourcetype=splunkd "Ignoring" AND "binary" | eval time=strftime(_time, "%m/%d/%y %H:%M:%S") | stats earliest(time) as start, latest(time) as stop by message, host
OR more efficient method (formatting should be done after aggregation, if possible/feasible)
index=_internal sourcetype=splunkd "Ignoring" AND "binary" | stats earliest(_time) as start, latest(_time) as stop by message, host | convert ctime(start) ctime(stop) timeformat="%m/%d/%y %H:%M:%S"
The field name created for formatted _time is not used in stats, hence the problem. Try like this
index=_internal sourcetype=splunkd "Ignoring" AND "binary" | eval time=strftime(_time, "%m/%d/%y %H:%M:%S") | stats earliest(time) as start, latest(time) as stop by message, host
OR more efficient method (formatting should be done after aggregation, if possible/feasible)
index=_internal sourcetype=splunkd "Ignoring" AND "binary" | stats earliest(_time) as start, latest(_time) as stop by message, host | convert ctime(start) ctime(stop) timeformat="%m/%d/%y %H:%M:%S"
Thank you somesoni2 for the solution.
Hi @jaho_splunk
If somesoni2's answer solved your question, please don't forget to resolve the post by clicking "Accept" directly below his answer and upvote him for being helpful. Thanks!