Splunk Search

How to calculate elapsed time only on working hours ?

clementros
Path Finder

Hi all, 

I'm trying to calculate the time support team took to respond when a new ticket is created. 

For now i'm able to calculate the duration between a status new and other next status of the ticket with the command transaction : 

| transaction "Record Number" startswith="New" endswith=eval(NOT match(_raw,"New"))
| table "Record Number", "PI Event Time", duration

 

Next step is to calculate this duration only on working hours. For that i need to substract duration value with weekend or holidays duration if there are between the start and end date ? 

For holidays i know i should create a lookup table with holidays with the same date format. But i do not know how to do the substraction time only if no working date are between start and end duration

Can you help me please ?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...