Hi I have a file with fields CloseDateTime and StartDateTime, both the field have a format like "2013-03-08 16:26 PM", I would like to have a separate field which will convert this format into single digit month and would require another field with date of the month.
Thanks.
The most robust approach would likely be to strptime your source fields and then to strftime them into whatever you like.
See docs on both here: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions