Find centralized, trusted content and collaborate around the technologies you use most.
Teams
Q&A for work
Connect and share knowledge within a single location that is structured and easy to search.
谁能为我提供一种让 Splunk 将当前以毫秒为单位的提取字段转换为 HH:MM:SS 的方法?
...| fieldFormat inSeconds = tostring(inMS/1000,"duration)
其中 inMS 是提取字段的名称, inSeconds 是您想要的结果
添加 | fields - inMS删除原始字段
| fields - inMS