<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Convert seconds into hours, minutes and seconds in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/539567#M152591</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/205856"&gt;@rijom&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could this be what you're looking for?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-to-h-mm-ss/m-p/291666" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-to-h-mm-ss/m-p/291666&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Feb 2021 19:49:24 GMT</pubDate>
    <dc:creator>yeasuh</dc:creator>
    <dc:date>2021-02-11T19:49:24Z</dc:date>
    <item>
      <title>How to convert seconds into hours, minutes and seconds?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87062#M22244</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;
&lt;P&gt;I'm not sure if somebody already asked a question like mine.&lt;BR /&gt;How can I convert a field containing a duartion (not a timestamp!) in seconds into hours, minutes and seconds?&lt;BR /&gt;E.g.:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;3855s --&amp;gt; 1h 4min 15s
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;Thanks&lt;BR /&gt;Simon&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 15:32:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87062#M22244</guid>
      <dc:creator>Simon</dc:creator>
      <dc:date>2022-05-05T15:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87063#M22245</link>
      <description>&lt;P&gt;Try this:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/439/how-to-convert-second-to-hhmmss-format-in-the-exported-search-result"&gt;http://splunk-base.splunk.com/answers/439/how-to-convert-second-to-hhmmss-format-in-the-exported-search-result&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2012 11:42:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87063#M22245</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-10-11T11:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87064#M22246</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
Thanx, so far I've seen this post already which worked fine. I was wondering if there's a built-in function available in the meantime.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2012 14:06:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87064#M22246</guid>
      <dc:creator>Simon</dc:creator>
      <dc:date>2012-10-11T14:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87065#M22247</link>
      <description>&lt;P&gt;Not that I am aware of.  I guess you could create your own custom search command but i don't know how much easier this makes your searches.  Probably not worth it.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/AdvancedDev/SearchScripts"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/AdvancedDev/SearchScripts&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2012 14:50:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87065#M22247</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-10-11T14:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87066#M22248</link>
      <description>&lt;P&gt;I think a macro will do it. Thanks for your answer!&lt;/P&gt;</description>
      <pubDate>Fri, 12 Oct 2012 10:53:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87066#M22248</guid>
      <dc:creator>Simon</dc:creator>
      <dc:date>2012-10-12T10:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87067#M22249</link>
      <description>&lt;P&gt;For those who're interested, see my macro (macros.conf):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[sla-sec2time(2)]
args = seconds,output_field
definition = eval sec2time_days=floor($seconds$/24/3600) | eval sec2time_hours=floor(($seconds$/3600)-(sec2time_days*24)) | eval sec2time_minutes = floor(($seconds$ / 60) - (sec2time_days*60*24) - (sec2time_hours * 60)) | eval sec2time_seconds = floor($seconds$ - (sec2time_days*3600*24) - (sec2time_hours * 3600) - (sec2time_minutes * 60)) | strcat sec2time_days " days " sec2time_hours "h " sec2time_minutes "m " sec2time_seconds "s" $output_field$
iseval = 0
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 12 Oct 2012 11:44:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87067#M22249</guid>
      <dc:creator>Simon</dc:creator>
      <dc:date>2012-10-12T11:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87068#M22250</link>
      <description>&lt;P&gt;Simon --  Your macro: sla-sec2time(2) is that the name of your index source? I need the same, per the below, and currently have a Days Hours Minutes Seconds column! &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; sigh.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2013 20:51:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87068#M22250</guid>
      <dc:creator>Xe03kfp</dc:creator>
      <dc:date>2013-02-11T20:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87069#M22251</link>
      <description>&lt;P&gt;There is an easier way! Assume that the field is named &lt;CODE&gt;secs&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;yoursearchhere
| convert rmunit(secs) as numSecs
| eval stringSecs=tostring(numSecs,"duration")
| eval stringSecs = replace(stringSecs,"(\d+)\:(\d+)\:(\d+)","\1h \2min \3s")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The resulting formatted string is called &lt;CODE&gt;stringSecs&lt;/CODE&gt;, although you could use the original field name in the last eval.&lt;BR /&gt;
BTW I would leave off the last eval and see if that will work for you.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2016 00:17:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87069#M22251</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2016-01-06T00:17:47Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87070#M22252</link>
      <description>&lt;P&gt;this is awesome, thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2016 13:48:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87070#M22252</guid>
      <dc:creator>mrickert91</dc:creator>
      <dc:date>2016-05-04T13:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87071#M22253</link>
      <description>&lt;P&gt;Note that this does not work if numSecs=0, as tostring returns 00:00:00 and the regex does not match.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| convert rmunit(secs) as numSecs
| eval stringSecs=tostring(numSecs,"duration")
| eval stringSecs = replace(stringSecs,"(\d+)\:(\d+)\:(\d+)","\1h \2min \3s")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;add&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| convert rmunit(secs) as numSecs
| eval stringSecs=tostring(numSecs,"duration")
| eval stringSecs=case(stringSecs="00:00:00", "0+0:0:0", 0=0, stringSecs)
| eval stringSecs = replace(stringSecs,"(\d+)\:(\d+)\:(\d+)","\1h \2min \3s")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;fixed it, not especially elegant...&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2016 20:25:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87071#M22253</guid>
      <dc:creator>andygerber</dc:creator>
      <dc:date>2016-09-13T20:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87072#M22254</link>
      <description>&lt;P&gt;I realise this is getting a bit old, but in case it helps someone else (like this helped me!), I'll share my extension of this answer.&lt;/P&gt;

&lt;P&gt;I wanted to include &lt;STRONG&gt;days&lt;/STRONG&gt; in the result, and remove leading zeroes from terms, and leading terms if they were zero.  This is my query:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eval string_dur = tostring(round(secs), "duration") 
| eval formatted_dur = replace(string_dur,"(?:(\d+)\+)?0?(\d+):0?(\d+):0?(\d+)","\1d \2h \3m \4s")
| eval result=replace(formatted_dur, "^d (0h (0m )?)?","") 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Sample results (including intermediate strings):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;secs         string_dur   formatted_dur    result
-----------  -----------  ---------------  ---------------
      2.000  00:00:02     d 0h 0m 2s       2s  
     12.500  00:00:13     d 0h 0m 13s      13s  
    144.333  00:02:24     d 0h 2m 24s      2m 24s  
   1728.250  00:28:48     d 0h 28m 48s     28m 48s  
  20736.200  05:45:36     d 5h 45m 36s     5h 45m 36s  
 248832.167  2+21:07:12   2d 21h 7m 12s    2d 21h 7m 12s  
2985984.143  34+13:26:24  34d 13h 26m 24s  34d 13h 26m 24s  
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 16 Apr 2018 03:21:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87072#M22254</guid>
      <dc:creator>tallpaulf</dc:creator>
      <dc:date>2018-04-16T03:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87073#M22255</link>
      <description>&lt;P&gt;Use eval() and then try to convert into h:m:s&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 07:47:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/87073#M22255</guid>
      <dc:creator>sheshanath</dc:creator>
      <dc:date>2019-08-23T07:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/525925#M148432</link>
      <description>&lt;P&gt;Looks like the link is no longer working or never worked in the past (there isnt a splunk-base.splunk.com anymore it seams.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 22:37:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/525925#M148432</guid>
      <dc:creator>cmeisch</dc:creator>
      <dc:date>2020-10-21T22:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/533992#M150908</link>
      <description>&lt;P&gt;This is a smal and good solution.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval time=tostring(filed_with_seconds, "duration")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will convert &lt;STRONG&gt;134&lt;/STRONG&gt; to &lt;STRONG&gt;00:02:14&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2020 20:38:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/533992#M150908</guid>
      <dc:creator>jotne</dc:creator>
      <dc:date>2020-12-23T20:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/539561#M152587</link>
      <description>&lt;P&gt;Broken link &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 19:32:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/539561#M152587</guid>
      <dc:creator>rijom</dc:creator>
      <dc:date>2021-02-11T19:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/539567#M152591</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/205856"&gt;@rijom&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could this be what you're looking for?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-to-h-mm-ss/m-p/291666" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-to-h-mm-ss/m-p/291666&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 19:49:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/539567#M152591</guid>
      <dc:creator>yeasuh</dc:creator>
      <dc:date>2021-02-11T19:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/596552#M207674</link>
      <description>&lt;P&gt;Hi.&lt;BR /&gt;&lt;BR /&gt;Followed instructions, build a query:&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;My_Search&lt;/FONT&gt;&lt;BR /&gt;|rename "nodes{}.hostname" as "Host Name"&lt;BR /&gt;|rename "nodes{}.uptime_seconds" as uptime_seconds&lt;BR /&gt;|eval UP_TIME = tostring(round(secs), "duration")&lt;BR /&gt;|eval UpTime = replace(UP_TIME,"(?:(\d+)\+)?0?(\d+):0?(\d+):0?(\d+)","\1d \2h \3m \4s")&lt;BR /&gt;|eval result=replace(UpTime, "^d (0h (0m )?)?","")&lt;BR /&gt;|table "Host Name", UpTime, "uptime_seconds"&amp;nbsp;&lt;BR /&gt;-------------------------&lt;BR /&gt;In the result table I gut value in "uptime_second" field, but not "in UpTime"&lt;BR /&gt;UpTime field is empty.&lt;BR /&gt;&lt;BR /&gt;Any sugestions?&lt;BR /&gt;&lt;BR /&gt;Thank you in advance&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 15:31:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/596552#M207674</guid>
      <dc:creator>bigll</dc:creator>
      <dc:date>2022-05-05T15:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/596554#M207675</link>
      <description>&lt;LI-CODE lang="markup"&gt;|eval UP_TIME = tostring(round(secs), "duration")&lt;/LI-CODE&gt;&lt;P&gt;should be&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|eval UP_TIME = tostring(round(uptime_seconds), "duration")&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 05 May 2022 15:45:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/596554#M207675</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-05-05T15:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Convert seconds into hours, minutes and seconds</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/597149#M207887</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 11:37:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-convert-seconds-into-hours-minutes-and-seconds/m-p/597149#M207887</guid>
      <dc:creator>bigll</dc:creator>
      <dc:date>2022-05-10T11:37:40Z</dc:date>
    </item>
  </channel>
</rss>

