<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Uptime Conversion in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Uptime-Conversion/m-p/555804#M157803</link>
    <description>&lt;P&gt;That was the solution.&amp;nbsp; &amp;nbsp;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jun 2021 14:50:21 GMT</pubDate>
    <dc:creator>cinsley</dc:creator>
    <dc:date>2021-06-15T14:50:21Z</dc:date>
    <item>
      <title>Uptime Conversion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Uptime-Conversion/m-p/555776#M157790</link>
      <description>&lt;P&gt;Below is a two result conversion table.&amp;nbsp; The data I am given, some will have days in the field and others will only have time.&amp;nbsp; How do I setup a conversion to handle this situation.&amp;nbsp; The convert auto(UpTime) works great as long as the field contains an entry with days.&amp;nbsp; The rex works well, again as long as the field contains a string containing days.&lt;/P&gt;&lt;P&gt;| makeresults&lt;BR /&gt;| eval UpTime="5:10:07:03.2419156"|append [|makeresults |eval UpTime="9:28:35.1006819"]&lt;BR /&gt;| convert auto(UpTime) AS autoDays&lt;BR /&gt;| rex field=UpTime "(?&amp;lt;days&amp;gt;\d+):(?&amp;lt;hours&amp;gt;\d+):(?&amp;lt;minutes&amp;gt;\d+):(?&amp;lt;seconds&amp;gt;\d+)\.(?&amp;lt;micro&amp;gt;\d+)"&lt;BR /&gt;| table UpTime, autoDays, days,hours,minutes, seconds, micro&lt;/P&gt;&lt;P&gt;Results:&lt;/P&gt;&lt;P&gt;UpTime&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; autoDays&amp;nbsp; days&amp;nbsp; &amp;nbsp; hours&amp;nbsp; &amp;nbsp;minutes seconds&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; micro&amp;nbsp;&lt;/P&gt;&lt;P&gt;5:10:07:03.2419156&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 5&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;10&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;07&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 03&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2419156&lt;BR /&gt;9:28:35.1006819&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 9&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 12:35:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Uptime-Conversion/m-p/555776#M157790</guid>
      <dc:creator>cinsley</dc:creator>
      <dc:date>2021-06-15T12:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: Uptime Conversion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Uptime-Conversion/m-p/555778#M157792</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222385"&gt;@cinsley&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval UpTime="5:10:07:03.2419156"|append [|makeresults |eval UpTime="9:28:35.1006819"]
| convert auto(UpTime) AS autoDays
| rex field=UpTime "((?&amp;lt;days&amp;gt;\d+):)?(?&amp;lt;hours&amp;gt;\d+):(?&amp;lt;minutes&amp;gt;\d+):(?&amp;lt;seconds&amp;gt;\d+)\.(?&amp;lt;micro&amp;gt;\d+)"
| table UpTime, autoDays, days,hours,minutes, seconds, micro&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 13:06:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Uptime-Conversion/m-p/555778#M157792</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-15T13:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Uptime Conversion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Uptime-Conversion/m-p/555804#M157803</link>
      <description>&lt;P&gt;That was the solution.&amp;nbsp; &amp;nbsp;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 14:50:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Uptime-Conversion/m-p/555804#M157803</guid>
      <dc:creator>cinsley</dc:creator>
      <dc:date>2021-06-15T14:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: Uptime Conversion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Uptime-Conversion/m-p/555807#M157805</link>
      <description>Glad to help you&lt;BR /&gt;&lt;BR /&gt;Happy Splunking</description>
      <pubDate>Tue, 15 Jun 2021 14:56:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Uptime-Conversion/m-p/555807#M157805</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-15T14:56:35Z</dc:date>
    </item>
  </channel>
</rss>

