can anyone provide me with a way to have Splunk convert an extracted field which is currently in milliseconds to HH:MM:SS?
Try
... | eval inSec = inMs / 1000 | fieldformat inSec = tostring(inSec, "duration")
where inMs
is the name of your extracted field
Try
... | eval inSec = inMs / 1000 | fieldformat inSec = tostring(inSec, "duration")
where inMs
is the name of your extracted field