Hi Team
How to convert millsec value to seconds
index=testing | timechart max("event.Properties.duration")
Can anyone helps to with spl query search converting value millsec value to seconds
Use this
index=testing
| timechart max("event.Properties.duration") as maxDuration
| eval maxDuration=round(maxDuration/1000, 3)
Here's an example, you can then change to your SPL fields
| makeresults
| eval millis_sec = 5000
| eval seconds = millis_sec/1000
| table millis_sec, seconds
Hi Deepak
I am bit confused using the time command
Filed name - event.Properties.duration
How do i execute this in the command.
I tried the below but sure i am missing something
index=testing | "event.Properties.duration"="*"
| makeresults
| eval millis_sec = 5000
| eval seconds = millis_sec/1000
| table millis_sec, seconds
@deepakc's was a so-called "run-anywhere" example. A sequence of commands that can be run on its own without any additional data that you need to search for, meant for showing some mechanism. It starts with a makeresults command which creates an "empty" result.
This example was not meant to be run as part of your search but you should do something similar with your data and your field names.
@jaibalaramanIf the time is in milliseconds, microseconds, or nanoseconds you must convert the time into seconds. You can use the pow function to convert the number.
Date and Time functions - Splunk Documentation
*** If the above solution helps, an upvote is appreciated. ***