Splunk Search

convert large duration timelapse to decimal hour

mjones414
Contributor

I'm trying to convert a timestamp where my hour will go beyone 24 hours: for example: 305:44:03 The ctime and dur2sec don't seem to be handling this timeformat properly with either "%H:%M:%S or %H%H%H:%M:%S or %k:%M:%S. and so on...

Tags (1)
0 Karma

chrisyounger
SplunkTrust
SplunkTrust

Well you could carve it up yourself like this:

| makeresults 
| eval val ="305:44:03" 
| rex field=val "(?<hr>\d+):(?<min>\d+):(?<sec>\d+)" 
| eval duration = (hr * 3600) + (min * 60) + sec 
| table duration

All the best

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...