I have a field as created time.
06-03-2018 13:03:51
06-03-2018 13:03:37
06-03-2018 13:03:38
i want only the date as "06-03-2018". i used strftime but couldnt convert it
HI @premranjithj,
try this:
...| eval temp=split(created_time," ")| eval created_time=mvindex(temp,0)
try this run anywhere search:
|makeresults|eval created_time="06-03-2018 13:03:51"| eval temp=split(created_time," ")| eval created_time=mvindex(temp,0)
HI @premranjithj,
try this:
...| eval temp=split(created_time," ")| eval created_time=mvindex(temp,0)
try this run anywhere search:
|makeresults|eval created_time="06-03-2018 13:03:51"| eval temp=split(created_time," ")| eval created_time=mvindex(temp,0)
created_time
06-03-2018
12:43:56
time stamps are in single fields but time is cumng in new line. how to ignore new line timestamp
if I understood correctly that if created_time is multivalue field then try this run anywhere search:
|makeresults|eval created_time="06-03-2018"
|append[|makeresults|eval created_time="13:03:51"]
|stats values(created_time) as created_time
| eval created_time=mvindex(created_time,0)
06-03-2018
12:43:56
time and date is a single value but time is cumng in new line.I dont want time
have you tried this:
...| eval created_time=mvindex(created_time,0)
yes it not worked
then try this regex:
...|rex field=created_time "(?<a>\S+)"
06-03-2018 13:03:51. how to change this into strftime(created_time"%y/%b/%d")
try this:
|eval created_time=strftime(strptime(created_time,"%d-%m-%Y %H:%M:%S"),"%Y/%b/%d")