Splunk Enterprise

Finding Duration and formatting output

scottmkirkland
Explorer

I'm having trouble getting my duration into the format I'd prefer... I'd like to see the duration to be MM:SS. However, despite a few different approaches, I keep getting milliseconds.

 

scottmkirkland_0-1741892584951.png

scottmkirkland_1-1741892748016.png

 

Labels (1)
Tags (1)
0 Karma

scottmkirkland
Explorer

Thank you @VatsalJagani 

I took that and I'm trying to get the avg response time for each year. AvgAtScene is in seconds, so I'm trying to get that into the duration. Any suggestions there?

scottmkirkland_0-1742398375547.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval AvgResponse=tostring(round(AvgAdScene,0),"duration")

ITWhisperer
SplunkTrust
SplunkTrust

Stop parsing the milliseconds from your time values, or convert the resultant time to an integer, or round the times to zero decimal places.

0 Karma

scottmkirkland
Explorer

@ITWhisperer Are you suggesting I just drop the %N in my strptime?

 

If I do that, my results don't change.

 

scottmkirkland_0-1741975158767.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
You should use round to seconds before (or inside) tostring function. That just drop ms away.
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@scottmkirkland- In your latest query you can just drop all millisecond zeros with the help of substr.

Example:

| eval secondsToAtScene = tonumber(substr(secondsToAtScene, 1, len(secondsToAtScene)-7))

This will just remove last 7 characters which will remove milliseconds part from it.

And you can apply this to any fields the same way.

 

Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...