Hi, i have a field in my logs that is date and time but it is in plain text not in time format. The field looks like this "Field=(Y/M/D h.m)".
Any suggestion how i can convert it so i can use it in time based queries?
Thanks
To convert the time field at index time, edit the TIME_FORMAT
attribute in your props.conf file. You may need to adjust other settings as well.
[mysourcetype]
TIME_PREFIX = FIELD=
TIME_FORMAT = %Y/%m/%d %H.%M
To convert the time field at search time, use the strptime
function.
... | eval ts = strptime(field, "%Y/%m/%d %H.%M") | ...