<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TimeFormat conversion to millisecond in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/TimeFormat-conversion-to-millisecond/m-p/212331#M62161</link>
    <description>&lt;P&gt;Great it worked now.&lt;/P&gt;

&lt;P&gt;I was checking the result using values(Field) and this was reordering the results.&lt;/P&gt;

&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jan 2017 09:18:45 GMT</pubDate>
    <dc:creator>hemendralodhi</dc:creator>
    <dc:date>2017-01-05T09:18:45Z</dc:date>
    <item>
      <title>TimeFormat conversion to millisecond</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TimeFormat-conversion-to-millisecond/m-p/212326#M62156</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have extracted field which contains application response time in below format.&lt;/P&gt;

&lt;P&gt;Format:&lt;/P&gt;

&lt;P&gt;00:00:00.000&lt;BR /&gt;
00:00:00.003&lt;BR /&gt;
00:00:00.545&lt;BR /&gt;
00:00:01.053&lt;BR /&gt;
00:00:29.544&lt;/P&gt;

&lt;P&gt;I need to convert it into millisecond or second. I tried using strptime and convert function but not working as expected. Can someone please advise?&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Hemendra&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2017 11:50:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TimeFormat-conversion-to-millisecond/m-p/212326#M62156</guid>
      <dc:creator>hemendralodhi</dc:creator>
      <dc:date>2017-01-03T11:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: TimeFormat conversion to millisecond</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TimeFormat-conversion-to-millisecond/m-p/212327#M62157</link>
      <description>&lt;P&gt;I would simply use rex for that (assuming your field name is myfield):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex field=myfield "(?&amp;lt;hour&amp;gt;\d{2}):(?&amp;lt;minute&amp;gt;\d{2}):(?&amp;lt;second&amp;gt;\d{2})\.(?&amp;lt;millisecond&amp;gt;\d{3})"
| eval durationInSeconds = hour * 3600 + minute * 60 + second + millisecond/1000
| eval durationInMilliseconds = durationInSeconds * 1000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| stats count | fields - count
| eval myfield = "01:01:29.544"
| rex field=myfield "(?&amp;lt;hour&amp;gt;\d{2}):(?&amp;lt;minute&amp;gt;\d{2}):(?&amp;lt;second&amp;gt;\d{2})\.(?&amp;lt;millisecond&amp;gt;\d{3})"
| eval durationInSeconds = hour * 3600 + minute * 60 + second + millisecond/1000
| eval durationInMilliseconds = durationInSeconds * 1000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Output:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;durationInSeconds
3689.544000 

durationInMilliseconds  
3689544.000 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 03 Jan 2017 12:10:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TimeFormat-conversion-to-millisecond/m-p/212327#M62157</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2017-01-03T12:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: TimeFormat conversion to millisecond</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TimeFormat-conversion-to-millisecond/m-p/212328#M62158</link>
      <description>&lt;P&gt;Thanks javiergn for your quick response. I tried with your method but it seems I am getting 2 values and also some are missing:&lt;/P&gt;

&lt;P&gt;Here is the actual field value:&lt;/P&gt;

&lt;P&gt;00:00:00.000&lt;BR /&gt;
00:00:00.002&lt;BR /&gt;
00:00:00.003&lt;BR /&gt;
00:00:00.005&lt;BR /&gt;
00:00:00.006&lt;/P&gt;

&lt;P&gt;Here is the Result:&lt;/P&gt;

&lt;P&gt;durationInSeconds   durationInMilliseconds&lt;BR /&gt;
0.123000    123.000&lt;BR /&gt;
0.123000    123.000&lt;BR /&gt;
0.109000    109.000&lt;BR /&gt;
0.109000    109.000&lt;BR /&gt;
0.148000    148.000&lt;BR /&gt;
0.148000    148.000&lt;BR /&gt;
0.043000    43.000&lt;BR /&gt;
0.043000    43.000&lt;BR /&gt;
0.084000    84.000&lt;BR /&gt;
0.084000    84.000&lt;BR /&gt;
0.143000    143.000&lt;BR /&gt;
0.143000    143.000&lt;BR /&gt;
0.033000    33.000&lt;BR /&gt;
0.033000    33.000&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2017 13:45:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TimeFormat-conversion-to-millisecond/m-p/212328#M62158</guid>
      <dc:creator>hemendralodhi</dc:creator>
      <dc:date>2017-01-03T13:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: TimeFormat conversion to millisecond</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TimeFormat-conversion-to-millisecond/m-p/212329#M62159</link>
      <description>&lt;P&gt;Look like my extracted field is behaving differently. When ran your rex search to see values in field got below. Not Sure why it is coming like this. Is it possible that it is related to string or numerical field value?&lt;/P&gt;

&lt;P&gt;hour    minute  second  millisecond&lt;BR /&gt;
00  00  00  123&lt;BR /&gt;
00  00  00  123&lt;BR /&gt;
00  00  00  109&lt;BR /&gt;
00  00  00  109&lt;BR /&gt;
00  00  00  148&lt;BR /&gt;
00  00  00  148&lt;BR /&gt;
00  00  00  043&lt;BR /&gt;
00  00  00  043&lt;BR /&gt;
00  00  00  084&lt;BR /&gt;
00  00  00  084&lt;BR /&gt;
00  00  00  143&lt;BR /&gt;
00  00  00  143&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2017 13:52:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TimeFormat-conversion-to-millisecond/m-p/212329#M62159</guid>
      <dc:creator>hemendralodhi</dc:creator>
      <dc:date>2017-01-03T13:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: TimeFormat conversion to millisecond</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TimeFormat-conversion-to-millisecond/m-p/212330#M62160</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Sorry I'm confused. Can you post the exact query you are running please (ensure you are using the code sample button otherwise it will escape some symbols) and also how your raw data looks like?&lt;/P&gt;

&lt;P&gt;In any case, I have tried replicating your example above and it seems to be working fine:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| stats count | fields - count
| eval myfield = split("00:00:00.000, 00:00:00.002, 00:00:00.003, 00:00:00.005, 00:00:00.006", ",")
| mvexpand myfield
| rex field=myfield "(?&amp;lt;hour&amp;gt;\d{2}):(?&amp;lt;minute&amp;gt;\d{2}):(?&amp;lt;second&amp;gt;\d{2})\.(?&amp;lt;millisecond&amp;gt;\d{3})"
| eval durationInSeconds = hour * 3600 + minute * 60 + second + millisecond/1000
| eval durationInMilliseconds = durationInSeconds * 1000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Output: see picture below&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://i.imgur.com/Ysk18Oa.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2017 15:47:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TimeFormat-conversion-to-millisecond/m-p/212330#M62160</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2017-01-03T15:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: TimeFormat conversion to millisecond</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TimeFormat-conversion-to-millisecond/m-p/212331#M62161</link>
      <description>&lt;P&gt;Great it worked now.&lt;/P&gt;

&lt;P&gt;I was checking the result using values(Field) and this was reordering the results.&lt;/P&gt;

&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2017 09:18:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TimeFormat-conversion-to-millisecond/m-p/212331#M62161</guid>
      <dc:creator>hemendralodhi</dc:creator>
      <dc:date>2017-01-05T09:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: TimeFormat conversion to millisecond</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TimeFormat-conversion-to-millisecond/m-p/212332#M62162</link>
      <description>&lt;P&gt;No worries.&lt;BR /&gt;
Please don't forget to mark it as answered so that others can benefit from it.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
J&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2017 13:20:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TimeFormat-conversion-to-millisecond/m-p/212332#M62162</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2017-01-05T13:20:24Z</dc:date>
    </item>
  </channel>
</rss>

