Splunk Search

How to extract days ,hours minutes and secs??

chitreshakumar
Communicator

I have got the duration in this format 11+09:45:25.591549.I want to convert it to 11 days 9 hours 45 mins 25 secs.

Tags (3)
0 Karma
1 Solution

DalJeanis
Legend

Here's one way...

| makeresults 
| eval myfield1="11+09:45:25.591549" 
| eval myfield2=myfield1 
| rex mode=sed field=myfield2 "s/(\d+)\+(\d+):(\d+):(\d+).(\d+)/\1 days \2 hours \3 mins \4 secs/g"
| table myfield1 myfield2

Above method assumes you will always have all pieces. If you will occasionally have durations that are shorter than a day and have zero days, zero hours or whatever, then you need to define what you want to receive.

View solution in original post

0 Karma

DalJeanis
Legend

Here's one way...

| makeresults 
| eval myfield1="11+09:45:25.591549" 
| eval myfield2=myfield1 
| rex mode=sed field=myfield2 "s/(\d+)\+(\d+):(\d+):(\d+).(\d+)/\1 days \2 hours \3 mins \4 secs/g"
| table myfield1 myfield2

Above method assumes you will always have all pieces. If you will occasionally have durations that are shorter than a day and have zero days, zero hours or whatever, then you need to define what you want to receive.

0 Karma

chitreshakumar
Communicator

Hi DalJeanis ,

There are some field values like this 00:00:10.000000 which I want to convert it to days , hours ,minutes and secs
Any way we can add " "00+" 00:00:10.000000"

0 Karma

DalJeanis
Legend

That should be something like this

 | makeresults 
 | eval myfield1="11+09:45:25.591549 00:00:10.000000"
 | makemv myfield1
 | mvexpand myfield1 
 | eval myfield2=myfield1 
 | rex mode=sed field=myfield2 "s/((\d+)\+)?(\d+):(\d+):(\d+).(\d+)/\2 days \3 hours \4 mins \5 secs/g s/^ /0 /g s/00/0/g"
 | table myfield1 myfield2
0 Karma

493669
Super Champion
rex field=<duration_field_name> "(?<DAYS>\d+).(?<Hours>\d+).(?<Mins>\d+).(?<Secs>\d+)"|table DAYS, Hours, Mins, Secs

replace <duration_field_name> with your duration field name

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...