<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Eval fields with decimals in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-eval-fields-with-decimals/m-p/618143#M50752</link>
    <description>&lt;P&gt;I am trying to restructure a data for this purpose&amp;nbsp;&lt;/P&gt;&lt;P&gt;For all MAC OS&amp;nbsp; between 10.15&amp;nbsp; and 10.99 =&amp;nbsp;&lt;A title="" href="https://en.wikipedia.org/wiki/Santa_Catalina_Island_(California)" target="_blank"&gt;Catalina&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For all MAC OS between 11:00 to 11:99 =&amp;nbsp;&lt;A title="Big Sur" href="https://en.wikipedia.org/wiki/Big_Sur" target="_blank"&gt;Big Sur&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For all MAC OS between 12:00 to 12:99 =&amp;nbsp;&lt;A title="Big Sur" href="https://en.wikipedia.org/wiki/Big_Sur" target="_blank"&gt;Monterey&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Field name is:&lt;/P&gt;&lt;P&gt;Base MAC OS&lt;/P&gt;&lt;P&gt;10.15.4&lt;/P&gt;&lt;P&gt;10.15.7&lt;/P&gt;&lt;P&gt;11.0&lt;/P&gt;&lt;P&gt;11.0.1&lt;/P&gt;&lt;P&gt;11.2&lt;/P&gt;&lt;P&gt;11.2.3&lt;/P&gt;&lt;P&gt;11.3.1&lt;/P&gt;&lt;P&gt;11.4&lt;/P&gt;&lt;P&gt;11.5.1&lt;/P&gt;&lt;P&gt;11.5.2&lt;/P&gt;&lt;P&gt;11.6&lt;/P&gt;&lt;P&gt;11.6.1&lt;/P&gt;&lt;P&gt;11.6.2&lt;/P&gt;&lt;P&gt;11.6.3&lt;/P&gt;&lt;P&gt;11.6.4&lt;/P&gt;&lt;P&gt;11.6.5&lt;/P&gt;&lt;P&gt;11.6.6&lt;/P&gt;&lt;P&gt;11.6.7&lt;/P&gt;&lt;P&gt;11.6.8&lt;/P&gt;&lt;P&gt;11.7&lt;/P&gt;&lt;P&gt;12.0.1&lt;/P&gt;&lt;P&gt;12.1&lt;/P&gt;&lt;P&gt;12.2&lt;/P&gt;&lt;P&gt;12.2.1&lt;/P&gt;&lt;P&gt;12.3&lt;/P&gt;&lt;P&gt;12.3.1&lt;/P&gt;&lt;P&gt;12.4&lt;/P&gt;&lt;P&gt;12.5&lt;/P&gt;&lt;P&gt;12.5.1&lt;/P&gt;&lt;P&gt;12.6&lt;/P&gt;</description>
    <pubDate>Mon, 24 Oct 2022 14:31:37 GMT</pubDate>
    <dc:creator>marceldera</dc:creator>
    <dc:date>2022-10-24T14:31:37Z</dc:date>
    <item>
      <title>How to eval fields with decimals?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-eval-fields-with-decimals/m-p/617965#M50738</link>
      <description>&lt;P&gt;I am trying to group range of decimal number: Range between 10.0.0 and10.15 =Medium&lt;/P&gt;
&lt;P&gt;10.16 -11=High&lt;/P&gt;
&lt;P&gt;11.1-11.5=critical&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for example:&lt;/P&gt;
&lt;P&gt;Severity&lt;/P&gt;
&lt;P&gt;10.15.4 12.6 12.6.0&lt;/P&gt;
&lt;P&gt;10.15.7&lt;/P&gt;
&lt;P&gt;10.15.7 10.15.7 12.6 12.6&lt;/P&gt;
&lt;P&gt;10.15.7 12.5.1 12.6 12.6.0&lt;/P&gt;
&lt;P&gt;10.15.7 12.6 12.6.0&lt;/P&gt;
&lt;P&gt;11.0 12.5.1&lt;/P&gt;
&lt;P&gt;11.0 12.6 12.6.0&lt;/P&gt;
&lt;P&gt;11.0.1 12.3.1 12.6 12.6.0&lt;/P&gt;
&lt;P&gt;11.2 12.6 12.6.0&lt;/P&gt;
&lt;P&gt;11.2.3 11.6.3 12.2.1 12.6 12.6.0&lt;/P&gt;
&lt;P&gt;11.2.3 12.6 12.6.0&lt;/P&gt;
&lt;P&gt;11.4 12.5.1&lt;/P&gt;
&lt;P&gt;11.4 12.5.1 12.5.1 12.6 12.6&lt;/P&gt;
&lt;P&gt;11.4 12.6 12.6.0&lt;/P&gt;
&lt;P&gt;11.5.1 12.6 12.6.0&lt;/P&gt;
&lt;P&gt;11.5.2 11.6.2 12.6 12.6.0&lt;/P&gt;
&lt;P&gt;11.5.2 11.7 11.7.0&lt;/P&gt;
&lt;P&gt;11.5.2 12.2.1 12.5.1&lt;/P&gt;
&lt;P&gt;11.5.2 12.2.1 12.6 12.6.0&lt;/P&gt;
&lt;P&gt;11.5.2 12.6 12.6.0&lt;/P&gt;
&lt;P&gt;11.6 11.6.0&lt;/P&gt;
&lt;P&gt;11.6 11.6.2 12.2.1 12.6 12.6.0&lt;/P&gt;
&lt;P&gt;11.6 11.6.2 12.3.1&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2022 14:46:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-eval-fields-with-decimals/m-p/617965#M50738</guid>
      <dc:creator>marceldera</dc:creator>
      <dc:date>2022-10-21T14:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: Eval fields with decimals</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-eval-fields-with-decimals/m-p/617970#M50739</link>
      <description>&lt;P&gt;A sequence of characters with more than one decimal point is not a number so Splunk will not treat it as such.&lt;/P&gt;&lt;P&gt;What problem are you trying to solve?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2022 12:23:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-eval-fields-with-decimals/m-p/617970#M50739</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-10-21T12:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: Eval fields with decimals</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-eval-fields-with-decimals/m-p/618143#M50752</link>
      <description>&lt;P&gt;I am trying to restructure a data for this purpose&amp;nbsp;&lt;/P&gt;&lt;P&gt;For all MAC OS&amp;nbsp; between 10.15&amp;nbsp; and 10.99 =&amp;nbsp;&lt;A title="" href="https://en.wikipedia.org/wiki/Santa_Catalina_Island_(California)" target="_blank"&gt;Catalina&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For all MAC OS between 11:00 to 11:99 =&amp;nbsp;&lt;A title="Big Sur" href="https://en.wikipedia.org/wiki/Big_Sur" target="_blank"&gt;Big Sur&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For all MAC OS between 12:00 to 12:99 =&amp;nbsp;&lt;A title="Big Sur" href="https://en.wikipedia.org/wiki/Big_Sur" target="_blank"&gt;Monterey&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Field name is:&lt;/P&gt;&lt;P&gt;Base MAC OS&lt;/P&gt;&lt;P&gt;10.15.4&lt;/P&gt;&lt;P&gt;10.15.7&lt;/P&gt;&lt;P&gt;11.0&lt;/P&gt;&lt;P&gt;11.0.1&lt;/P&gt;&lt;P&gt;11.2&lt;/P&gt;&lt;P&gt;11.2.3&lt;/P&gt;&lt;P&gt;11.3.1&lt;/P&gt;&lt;P&gt;11.4&lt;/P&gt;&lt;P&gt;11.5.1&lt;/P&gt;&lt;P&gt;11.5.2&lt;/P&gt;&lt;P&gt;11.6&lt;/P&gt;&lt;P&gt;11.6.1&lt;/P&gt;&lt;P&gt;11.6.2&lt;/P&gt;&lt;P&gt;11.6.3&lt;/P&gt;&lt;P&gt;11.6.4&lt;/P&gt;&lt;P&gt;11.6.5&lt;/P&gt;&lt;P&gt;11.6.6&lt;/P&gt;&lt;P&gt;11.6.7&lt;/P&gt;&lt;P&gt;11.6.8&lt;/P&gt;&lt;P&gt;11.7&lt;/P&gt;&lt;P&gt;12.0.1&lt;/P&gt;&lt;P&gt;12.1&lt;/P&gt;&lt;P&gt;12.2&lt;/P&gt;&lt;P&gt;12.2.1&lt;/P&gt;&lt;P&gt;12.3&lt;/P&gt;&lt;P&gt;12.3.1&lt;/P&gt;&lt;P&gt;12.4&lt;/P&gt;&lt;P&gt;12.5&lt;/P&gt;&lt;P&gt;12.5.1&lt;/P&gt;&lt;P&gt;12.6&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 14:31:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-eval-fields-with-decimals/m-p/618143#M50752</guid>
      <dc:creator>marceldera</dc:creator>
      <dc:date>2022-10-24T14:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to eval fields with decimals?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-eval-fields-with-decimals/m-p/618152#M50754</link>
      <description>&lt;P&gt;There may be other ways to do this, but here's one.&amp;nbsp; It converts the version strings into integers, which are easy to compare or test in ranges.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;...
| eval versint = split(version, ".")
```We use separate fields because printf won't accept mvindex as an argument```
| eval major=mvindex(versint, 0), minor=mvindex(versint,1), maint=mvindex(versint,2)
```Handle missing 3rd-level number```
| fillnull value=0 maint
| eval versint = printf("%02d%02d%02d", major, minor, maint)
...&lt;/LI-CODE&gt;&lt;P&gt;This assume each level of the version string can be a 2-digit number.&amp;nbsp; Feel free to adjust the &lt;FONT face="courier new,courier"&gt;printf &lt;/FONT&gt;format to allow for 3-digit number, if necessary.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 15:28:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-eval-fields-with-decimals/m-p/618152#M50754</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-10-24T15:28:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to eval fields with decimals?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-eval-fields-with-decimals/m-p/618153#M50755</link>
      <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;your base search
| eval OS_Name=case(match('Base MAC OS',"10\..*"),"Catalina", match('Base MAC OS',"11\..*"),"Big Sur",match('Base MAC OS',"12\..*"),"Monterey", true(),"Unknown")&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 24 Oct 2022 15:29:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-eval-fields-with-decimals/m-p/618153#M50755</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2022-10-24T15:29:25Z</dc:date>
    </item>
  </channel>
</rss>

