how to calculate incident end day SLA hours in splunk? I mean if Inc_Resolved_Time="27.02.2024 08:00" and TeamWorkTimings="Mon-Fri 7AM to 6PM", then the end day SLA hours should be 1business hour.
Could you please help me with splunk query to achieve this result. I am trying to use this query but not getting proper results::
| eval Ending_Day_SLA_Hours=if(((incidentEndTime1-incidentStartTime1)<86400 AND Inc_Open_Days=Inc_Resolved_Actual_Days),0,if((Inc_Resolve_Date=Weekend_1 OR Inc_Resolve_Date=Weekend_2 OR Inc_Resolve_Date=Weekend_3 OR Inc_Resolve_Date=Weekend_4),0,if((incidentEndTime1>Inc_SLA_Start_Day_Epoch AND incidentEndTime1>Inc_SLA_End_Day_Epoch),(660-((incidentEndTime1-Inc_SLA_End_Day_Epoch)/1440))/60,if(incidentEndTime1<Inc_SLA_Start_Day_Epoch,11,0))))
... View more