Hi All,
I have an output from a lookup table in splunk where the team work timings field is coming as::
TeamWorkTimings
09:00:00-18:00:00
I want the output to be separated in two fields, like:
TeamStart TeamEnd
09:00:00 18:00:00
Please help me in getting this output in splunk
| eval TeamStart=mvindex(split(TeamWorkTimings,"-"),0)
| eval TeamEnd=mvindex(split(TeamWorkTimings,"-"),1)
Thanks, this worked 🙂
| eval TeamStart=mvindex(split(TeamWorkTimings,"-"),0)
| eval TeamEnd=mvindex(split(TeamWorkTimings,"-"),1)