Splunk Search

Convert negative seconds to duration

joxley
Path Finder

I have a column of seconds, some of which are negative (representing an outage). I want to use tostring(duration, "duration") on the column, but that doesn't work

| stats count | eval count=-5 | eval duration=tostring(count, "duration")
1 Solution

joxley
Path Finder

Absolute the duration in the conversion and prepend it with a - or empty string.

| stats count | eval count=-5 | eval duration=if(count<0, "-", "") + tostring(abs(count), "duration")

View solution in original post

0 Karma

joxley
Path Finder

Absolute the duration in the conversion and prepend it with a - or empty string.

| stats count | eval count=-5 | eval duration=if(count<0, "-", "") + tostring(abs(count), "duration")
0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes & Cloud Monitoring with Splunk IM

Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team on ...

Index This | What did the zero say to the eight?

June 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

Splunk Observability Cloud's AI Assistant in Action Series: Onboarding New Hires & ...

This is the fifth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...