Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to format 84601 seconds as 24:00:01

$
0
0
I am trying to display a duration result to a dashboard and when I try to use the function to convert seconds to HH:MM:SS format like this: index="ourlogs" | eval OurNameDDHHMMSS=tostring(OurVariable, "duration") Anything over 24 hours (84600 seconds) the result I see is 1+00:00:01. When I do a search and I ask for the top 2 (using head 2) I am getting the 23:00:00 numbers returned instead of anything with the 1+ format. I also think for the people who look at the dashboard it would be easier for them to see it as 24:00:01. Any suggestions or links would be appreciated. Thanks

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>