Hi,
I have a table with duration in seconds, how can I convert it to [h]:mm:ss? I want it to count the number of hours even if it is more than 1 day. Thanks!
Here is my query.
| dedup IDEVENT
| where _time>relative_time(now(),"-4w@w")
| bin _time span=1w
| stats sum(DURATION) as eventduration by DESCRIPTION _time
Hi
Can you please try | eval time=strftime(_time, "%H:%M:%S")
or you can try | eval time=tostring(_time,"duration")
So your query will be
| dedup IDEVENT
| where _time>relative_time(now(),"-4w@w")
| bin _time span=1w
| stats sum(DURATION) as eventduration by DESCRIPTION _time
| eval time=strftime(_time, "%H:%M:%S")
and with second approach
| dedup IDEVENT
| where _time>relative_time(now(),"-4w@w")
| bin _time span=1w
| stats sum(DURATION) as eventduration by DESCRIPTION _time
| eval time=tostring(_time,"duration")
Hi
Can you please try | eval time=strftime(_time, "%H:%M:%S")
or you can try | eval time=tostring(_time,"duration")
So your query will be
| dedup IDEVENT
| where _time>relative_time(now(),"-4w@w")
| bin _time span=1w
| stats sum(DURATION) as eventduration by DESCRIPTION _time
| eval time=strftime(_time, "%H:%M:%S")
and with second approach
| dedup IDEVENT
| where _time>relative_time(now(),"-4w@w")
| bin _time span=1w
| stats sum(DURATION) as eventduration by DESCRIPTION _time
| eval time=tostring(_time,"duration")
@harsmarvania57 , thanks! The second approach works! 🙂
@auaave, Glad to hear that it worked, please accept my answer and upvote it. 🙂
Hi Auaave,
You can use strftime function using eval. For eg.
eval eventduration=strftime(eventduration,"%H:%M:%S")
@p_gurav, thanks for your reply. 🙂