<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Rex command to extract time duration in hh:mm:ss in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475879#M133708</link>
    <description>&lt;P&gt;can you just post it to your question?&lt;/P&gt;</description>
    <pubDate>Tue, 05 Nov 2019 20:07:53 GMT</pubDate>
    <dc:creator>marycordova</dc:creator>
    <dc:date>2019-11-05T20:07:53Z</dc:date>
    <item>
      <title>Using Rex command to extract time duration in hh:mm:ss</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475874#M133703</link>
      <description>&lt;P&gt;Hello, I am trying to extract data, specifically time data in hh:mm:ss:nn format and put it on a table.  When I do, I get no results to show up on my code.  &lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 18:53:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475874#M133703</guid>
      <dc:creator>harshparikhxlrd</dc:creator>
      <dc:date>2019-11-05T18:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: Using Rex command to extract time duration in hh:mm:ss</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475875#M133704</link>
      <description>&lt;P&gt;post a sample of your data please&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 19:01:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475875#M133704</guid>
      <dc:creator>marycordova</dc:creator>
      <dc:date>2019-11-05T19:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: Using Rex command to extract time duration in hh:mm:ss</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475876#M133705</link>
      <description>&lt;P&gt;Try this for help: &lt;A href="https://regex101.com/"&gt;https://regex101.com/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 19:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475876#M133705</guid>
      <dc:creator>marycordova</dc:creator>
      <dc:date>2019-11-05T19:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Using Rex command to extract time duration in hh:mm:ss</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475877#M133706</link>
      <description>&lt;P&gt;&lt;A href="https://textuploader.com/1kbvy"&gt;https://textuploader.com/1kbvy&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 19:09:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475877#M133706</guid>
      <dc:creator>harshparikhxlrd</dc:creator>
      <dc:date>2019-11-05T19:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: Using Rex command to extract time duration in hh:mm:ss</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475878#M133707</link>
      <description>&lt;P&gt;Added my data sample to post.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 19:10:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475878#M133707</guid>
      <dc:creator>harshparikhxlrd</dc:creator>
      <dc:date>2019-11-05T19:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: Using Rex command to extract time duration in hh:mm:ss</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475879#M133708</link>
      <description>&lt;P&gt;can you just post it to your question?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 20:07:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475879#M133708</guid>
      <dc:creator>marycordova</dc:creator>
      <dc:date>2019-11-05T20:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: Using Rex command to extract time duration in hh:mm:ss</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475880#M133709</link>
      <description>&lt;P&gt;I can't.  It won't let me post the whole data.  &lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 20:10:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475880#M133709</guid>
      <dc:creator>harshparikhxlrd</dc:creator>
      <dc:date>2019-11-05T20:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: Using Rex command to extract time duration in hh:mm:ss</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475881#M133710</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;| makeresults
| eval _raw="11/05/2019 10:21:04 AM
LogName=Application
SourceName=RoboticLogging
EventCode=0
EventType=4
Type=Information
ComputerName=WTWFBVZP.UNITOPR.UNITINT.TEST.STATEFARM.ORG
TaskCategory=%1
OpCode=Info
RecordNumber=51614
Keywords=Classic
Message=&amp;lt;Robotics Workstation=\"WTWFBVZP\" UserID=\"UNTOPR\OE1OTD\" Department=\"HRSS_NEO\" TaskID=\"Daily NEO Report\" Automation=\"NEO_P_SplunkMetrics\" Message=\"Number of supervisor reminder memos sent: 6,Number of New Employees in NEO Report without job title Temporary Agy Svc Asst: 988,Number of New Employees in NEO Report with job title Temporary Agy Svc Asst: 23,Duration: 00:01:50.5270509\" AdditionalInfo1=\"NA\" AdditionalInfo2=\"NA\""
| kv
| eval _time=mvindex(split(_raw,"
"),0)
| eval _time=strptime(_time,"%m/%d/%Y %T %p")
| fieldformat _time=strftime(_time,"%m/%d/%Y %T %p")
| rex "Message=\"(?&amp;lt;Message&amp;gt;[^\"]+)\""
| table _time LogName SourceName EventCode EventType Type ComputerName TaskCategory OpCode RecordNumber Keywords
,Workstation UserID Department TaskID Automation Message AdditionalInfo1 AdditionalInfo2
| appendpipe 
    [eval _raw = Message
    | eval _raw = replace(_raw,"(\d+:\d+:\d+\.\d+)","\"\1\"")
    | extract pairdelim="," kvdelim=":"
    | fields - _raw]
    | selfjoin Message
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hi, folks.&lt;BR /&gt;
That's all?&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jan 2020 10:43:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-Rex-command-to-extract-time-duration-in-hh-mm-ss/m-p/475881#M133710</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-01-19T10:43:05Z</dc:date>
    </item>
  </channel>
</rss>

