I have two fields in a single search row. start_time and end_time. they are both in the format HH:MM:SS. I'd like to calculate the duration end_time - start_time and have the results in the same format HH:MM:SS.
thanks!
To get the duration in the new field dur
;
...| eval st=strptime(start_time, "%H:%M:%S") | eval et=strptime(end_time,"%H:%M:%S") | eval diff = et - st | eval dur = tostring(diff, "duration")
Read more on eval
functions here;
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions
/k