Splunk Search

Converting the result from my search

exchanger
Path Finder

Hello, i think its not that difficult, but i dont know how to do it.

 

The result is in milliseconds. Is there an easy way to convert these milliseconds into seconds?

 

Best regards

Labels (1)
0 Karma
1 Solution

KailA
Contributor

Hello exchanger,

You can use the eval fonction.

Try this :

 

Your search
| stats avg(duration) as avg_duration, perc50(duration) as perc50_duration, perc75(duration) as perc75_duration, max(duration) as max_duration
| eval avg_duration = avg_duration / 1000

 And you can do that for each field if you want.

Let me know if it helps you 🙂

View solution in original post

KailA
Contributor

Hello exchanger,

You can use the eval fonction.

Try this :

 

Your search
| stats avg(duration) as avg_duration, perc50(duration) as perc50_duration, perc75(duration) as perc75_duration, max(duration) as max_duration
| eval avg_duration = avg_duration / 1000

 And you can do that for each field if you want.

Let me know if it helps you 🙂

exchanger
Path Finder

@KailA 

Yes thats works perfect. Thanks 🙂 

Another last question: 

I have more then one search

Like first query

my search 

second query

my search2  

third query...

Is there a way to combine these queries, so that i can search multiple queries with one search?

Tags (1)
0 Karma

KailA
Contributor

Yes it's possible.

The worst (but working) solution is using the append function (https://docs.splunk.com/Documentation/Splunk/8.1.2/SearchReference/Append)

I said worst because it's not the most efficient way.

If you need help for that you should create another post, and if possible put all the queries you want to merge, someone will help you 🙂

For this post, you can mark my answer as the solution to close it

0 Karma

exchanger
Path Finder

Thanks for this information. I used the append function and it worked 🙂 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...