<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Convert Number to Hour in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550063#M9055</link>
    <description>&lt;P&gt;It looks like you are doing it correctly. Can you share the full search (anonymised where necessary) so we can see where the issue might be coming from?&lt;/P&gt;</description>
    <pubDate>Fri, 30 Apr 2021 17:57:42 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2021-04-30T17:57:42Z</dc:date>
    <item>
      <title>Convert Number to Hour</title>
      <link>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550041#M9050</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I need to convert the specific number&amp;nbsp; from 0 to 23 to 00:00:00 format.&amp;nbsp; I used the following in my statement by I am getting a blank on my eventHour field.&lt;/P&gt;&lt;P&gt;eval HOUR=(if (isnull(HOUR),"0",HOUR)) | eval eventHour=strftime(strptime(HOUR,"%k"),"%H")&lt;/P&gt;&lt;P&gt;This will be used to rebuild the _time&lt;/P&gt;&lt;P&gt;eval _time=strptime(DATE." ".HOUR,"%Y-%m-%d %H:%M:%S")&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 16:51:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550041#M9050</guid>
      <dc:creator>aquinojason</dc:creator>
      <dc:date>2021-04-30T16:51:43Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Number to Hour</title>
      <link>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550050#M9051</link>
      <description>&lt;LI-CODE lang="markup"&gt;| eval HOUR=if (isnull(HOUR),"0",HOUR)
| eval eventHour=substr("0".HOUR,-2,2).":00:00"
| eval _time=strptime(DATE." ".eventHour,"%Y-%m-%d %H:%M:%S")&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 30 Apr 2021 17:16:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550050#M9051</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-04-30T17:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Number to Hour</title>
      <link>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550054#M9052</link>
      <description>&lt;P&gt;Thank you. But would you know why I am getting this as _time result?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aquinojason_0-1619803489645.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14003i816046BB37F52A70/image-size/medium?v=v2&amp;amp;px=400" role="button" title="aquinojason_0-1619803489645.png" alt="aquinojason_0-1619803489645.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 17:25:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550054#M9052</guid>
      <dc:creator>aquinojason</dc:creator>
      <dc:date>2021-04-30T17:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Number to Hour</title>
      <link>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550059#M9053</link>
      <description>&lt;P&gt;Is DATE a multivalue field perhaps?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 17:33:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550059#M9053</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-04-30T17:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Number to Hour</title>
      <link>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550062#M9054</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Sorry but what do you mean by multivalue?&amp;nbsp; The DATE from our input is formatted as 01JAN2021 so I used&lt;/P&gt;&lt;P&gt;eval DATE=strftime(strptime(DATE,"%d%b%Y"),"%Y-%m-%d") to reformat it.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 17:53:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550062#M9054</guid>
      <dc:creator>aquinojason</dc:creator>
      <dc:date>2021-04-30T17:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Number to Hour</title>
      <link>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550063#M9055</link>
      <description>&lt;P&gt;It looks like you are doing it correctly. Can you share the full search (anonymised where necessary) so we can see where the issue might be coming from?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 17:57:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550063#M9055</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-04-30T17:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Number to Hour</title>
      <link>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550065#M9056</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Here is my full search.&lt;/P&gt;&lt;P&gt;index=index1 sourcetype=sourcertype1 MVS_SYSTEM_ID != MVS_SYSTEM_ID | multikv forceheader=1 | dedup ACCOUNT_CODE DATE MVS_SYSTEM_ID CALCMIPS | eval DATE=strftime(strptime(DATE,"%d%b%Y"),"%Y-%m-%d") | lookup lookup.csv ACCOUNT_CODE OUTPUT Application BusinessUnit ApplicationRTO | eval Application=(if (isnull(Application),"Others",Application)) | eval BusinessUnit=(if (isnull(BusinessUnit),"Others",BusinessUnit)) | eval HOUR=if (isnull(HOUR),"0",HOUR) | eval eventHour=substr("0".HOUR,-2,2).":00:00" | eval _time=strptime(DATE." ".eventHour,"%Y-%m-%d %H:%M:%S") | table Application BusinessUnit DATE SYSTEM_ID CALCMIPS eventHour _time | chart avg(CALCMIPS) over _time span=1mon by BusinessUnit limit=0&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 18:05:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550065#M9056</guid>
      <dc:creator>aquinojason</dc:creator>
      <dc:date>2021-04-30T18:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Number to Hour</title>
      <link>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550135#M9058</link>
      <description>&lt;P&gt;It's look like there is an issue with the input itself so it is not being converted properly. Thanks for the help!&lt;/P&gt;</description>
      <pubDate>Sun, 02 May 2021 07:14:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Convert-Number-to-Hour/m-p/550135#M9058</guid>
      <dc:creator>aquinojason</dc:creator>
      <dc:date>2021-05-02T07:14:39Z</dc:date>
    </item>
  </channel>
</rss>

