Splunk Search

How to calculate elapsed time only on working hours ?

clementros
Path Finder

Hi all, 

I'm trying to calculate the time support team took to respond when a new ticket is created. 

For now i'm able to calculate the duration between a status new and other next status of the ticket with the command transaction : 

| transaction "Record Number" startswith="New" endswith=eval(NOT match(_raw,"New"))
| table "Record Number", "PI Event Time", duration

 

Next step is to calculate this duration only on working hours. For that i need to substract duration value with weekend or holidays duration if there are between the start and end date ? 

For holidays i know i should create a lookup table with holidays with the same date format. But i do not know how to do the substraction time only if no working date are between start and end duration

Can you help me please ?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...