I have a field called DATE and it is returning values yyyy-mm-dd HH:MM:SS. I am trying to chop off the hours, min, seconds so I only have yyyy-mm-dd. I have tried to use the convert command but I would rather not have to convert it to epoch time and then convert it back. Is there an easier way to go about this?
Thank you in advance
the most efficient way is to set up TIME_FORMAT in props.conf . That will do the magic at indexing time
| eval n=strptime(DATE, "%Y-%m-%d") | convert timeformat="%Y %m %d" ctime(n) AS c_time | chart count by c_time
this gave me the count for each day i requested, thank you for the help
If Splunk is not already parsing out this field , you can use something like such:
...|rex field=DATE mode=sed "/s/\d{2}:\d{2}:\d{2}//g"