Splunk Search

How can I change duration [5s] to something I can calculate with?

svester
New Member

Hi, I made a search, and want to finetune it with something like "show duration >20seconds", but duration is showed as "duration [8s]". I tried extracting field and make "duration [8s]" a new extracted field, but I don't know how to calculate with these brackets, or how to define it.
Anyone who can help me out? Thanks!

Tags (1)
0 Karma
1 Solution

dkeck
Influencer

Hi,

so your field value is now "duration [8s]"?

than use this regex: duration\s+\[(?<field>\d+)

This will only give you the numbers.

View solution in original post

svester
New Member

One more problem I'm bumping in now.. what if I also get [..ms], so milliseconds... And I'm searching for, let's say duration>20, now I get results with >20 seconds AND >20 milliseconds. 2 regexes? Any other suggestions?

0 Karma

dkeck
Influencer

you can do a new field yes.

You can change the name of the field to "field_a" duration\s+\[(?<field_a>\d+).

So just give it a name where you now its milliseconds.

0 Karma

dkeck
Influencer

Hi,

so your field value is now "duration [8s]"?

than use this regex: duration\s+\[(?<field>\d+)

This will only give you the numbers.

svester
New Member

Thanks! It worked 🙂

0 Karma

dkeck
Influencer

Please accept my answer if it worked 🙂 Thank you

0 Karma

svester
New Member

Sorry, will do 🙂 Could you please check my 2nd comment? 🙂

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...