Hi All,
I have time field having time range in this format in output of one splunk query:
TeamWorkTimings
09:00:00-18:00:00
I want to have the values stored in two fields like:
TeamStart
09:00:00
TeamEnd
18:00:00
How do I achieve this using regex or concat expression in splunk. Please suggest.
thanks, it worked 🙂
One more request, since I am new to splunk, could you please help me understand how this regular expression works, I mean what does this means in a regex expression:
| rex field=TeamWorkTimings "(?<TeamStart>[^-]+)-(?<TeamEnd>.*)"
regex101.com is a good site to test and understand regular expressions
I have set this one up to show your extraction
https://regex101.com/r/mBRfJF/1
Try something like this
| rex field=TeamWorkTimings "(?<TeamStart>[^-]+)-(?<TeamEnd>.*)"