How do I convert 2016-06-17T14:16
to 2016-06-17 14:16:00
format in Splunk? Appreciate your help.
You can use eval strftime and strptime for those types of changes: http://docs.splunk.com/Documentation/Splunk/6.4.1/SearchReference/CommonEvalFunctions.
Is the time you specified in the _time field or in another field?
It is another field I've extracted. In that case how do I convert?
If you just want to remove the "T", you can use:
| eval field2=replace(field1, "T", " ")