Getting Data In

convert time format

avi123
Explorer

Hi All, 

I have a splunk query returning output as:

STime

09:45

 

I want to convert it to hours. Expected output:

STime

9.75 hrs

 

How do I achieve this using splunk

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This run-anywhere example should explain the process.

| makeresults 
| eval STime="9:45"
| rex field=STime "(?<hrs>\d+):(?<mins>\d+)"
| eval Hours=hrs + round(mins/60,2)
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...