Splunk Enterprise

Finding Duration and formatting output

scottmkirkland
Explorer

I'm having trouble getting my duration into the format I'd prefer... I'd like to see the duration to be MM:SS. However, despite a few different approaches, I keep getting milliseconds.

 

scottmkirkland_0-1741892584951.png

scottmkirkland_1-1741892748016.png

 

Labels (1)
Tags (1)
0 Karma

scottmkirkland
Explorer

Thank you @VatsalJagani 

I took that and I'm trying to get the avg response time for each year. AvgAtScene is in seconds, so I'm trying to get that into the duration. Any suggestions there?

scottmkirkland_0-1742398375547.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval AvgResponse=tostring(round(AvgAdScene,0),"duration")

ITWhisperer
SplunkTrust
SplunkTrust

Stop parsing the milliseconds from your time values, or convert the resultant time to an integer, or round the times to zero decimal places.

0 Karma

scottmkirkland
Explorer

@ITWhisperer Are you suggesting I just drop the %N in my strptime?

 

If I do that, my results don't change.

 

scottmkirkland_0-1741975158767.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
You should use round to seconds before (or inside) tostring function. That just drop ms away.
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@scottmkirkland- In your latest query you can just drop all millisecond zeros with the help of substr.

Example:

| eval secondsToAtScene = tonumber(substr(secondsToAtScene, 1, len(secondsToAtScene)-7))

This will just remove last 7 characters which will remove milliseconds part from it.

And you can apply this to any fields the same way.

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...