Hi All,
i have to convert an extracted field "responcetime" values like ":1389 ms",":345 ms" to number format .as the above field is of type as string its doing sorting as string but want it as number sorting so please help me.
Thanks in advance
Ravi
Just make sure that the "responcetime" field only holds numbers, and Splunk should handle it numerically automatically. For instance you could use rex
.
... | rex field=responcetime "^:(?<responcetime>\d+)" | ...
Just make sure that the "responcetime" field only holds numbers, and Splunk should handle it numerically automatically. For instance you could use rex
.
... | rex field=responcetime "^:(?<responcetime>\d+)" | ...
Thank u so much Ayn its worked perfectly now.
Regards
Ravi