Splunk Search

Calculating duration from a number

whipstash
Engager

I am trying to find the duration for a time span. The "in" and "out" numbers are included in the data as type: number. I attempted:

in = 20240401183030

out = 20240401193030

| convert mktime(in) AS IN
| convert mktime(out) AS OUT
| eval Duration =OUT - IN

I have not been able to find a function that would directly convert number to time or if there is some multifunctional way to get the right duration between the two,

But this does not perform the correct time math. 

0 Karma

whipstash
Engager

Thanks ITWhisperer! I did try the string conversion, but it did not work. This looks like it did the trick!

0 Karma

PickleRick
SplunkTrust
SplunkTrust

The "convert mktime()" could also be the way to go but you need to specify the time format with... the "timeformat=" option. Otherwise Splunk has to guess and usually guesses wrong.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval IN = strptime(in, "%Y%m%d%H%M%S")
| eval OUT = strptime(out, "%Y%m%d%H%M%S")
| eval Duration = tostring(OUT - IN,"duration")
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...