Getting Data In

convert time format

avi123
Explorer

Hi All, 

I have a splunk query returning output as:

STime

09:45

 

I want to convert it to hours. Expected output:

STime

9.75 hrs

 

How do I achieve this using splunk

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This run-anywhere example should explain the process.

| makeresults 
| eval STime="9:45"
| rex field=STime "(?<hrs>\d+):(?<mins>\d+)"
| eval Hours=hrs + round(mins/60,2)
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...