Splunk Search

format output of a string in a particular format?

erhksadhwani
New Member

I have a search query that returns numbers like 170503007 and 170504021 as outputs. Need to format them as 2017/05/03 007 and 2017/05/04 021

Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Here's one way.

... | rex field=foo "(?<yr>\d\d)(?<mon>\d\d)(?<day>\d\d)(?<num>\d{3})" | eval output="20".yr."/".mon."/".day." ".num | ...
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...