<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do I create new columns with the foreach command? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-new-columns-with-the-foreach-command/m-p/412472#M118920</link>
    <description>&lt;P&gt;Hello, I have a question about the use of the &lt;CODE&gt;foreach&lt;/CODE&gt; command. I have a good idea what the &lt;CODE&gt;foreach&lt;/CODE&gt; command can do for example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=summary source="summary_events_2" 
orig_source=$source$
ms_region=$region$
ms_level=$level$
| timechart span=5m  partial=f sum(count) as count
| timewrap d series=short
| rename s0 as Today
| foreach s*
     [eval d&amp;lt;&amp;lt;MATCHSTR&amp;gt;&amp;gt; = Today - &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I know that this will create new columns like &lt;CODE&gt;d1,d2,d3,d4,...&lt;/CODE&gt; that will contain the difference of &lt;CODE&gt;Today&lt;/CODE&gt; and &lt;CODE&gt;s*&lt;/CODE&gt; .&lt;/P&gt;

&lt;P&gt;Here is my dilemma: what if I do something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   index=summary source="summary_events_2" 
     orig_source=$source$
     ms_region=$region$
     ms_level=$level$
     | timechart span=5m  partial=f sum(count) as count by ms_level        (//note that there are 4 levels)
     | timewrap d series=short
     | rename *_s0 as *_Today
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This would give me columns like &lt;CODE&gt;ERROR_Today, WARNING_TODAY, ERROR_s1, ERROR_s2,WARNING_s1....&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Is there a way to achieve the same result as the first query using the &lt;CODE&gt;foreach&lt;/CODE&gt; command. I want to be able to create new columns like &lt;CODE&gt;ERROR_d1, ERROR_d2, WARNING_d1, WARNING_d2&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Oct 2018 16:26:52 GMT</pubDate>
    <dc:creator>kiamco</dc:creator>
    <dc:date>2018-10-09T16:26:52Z</dc:date>
    <item>
      <title>How do I create new columns with the foreach command?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-new-columns-with-the-foreach-command/m-p/412472#M118920</link>
      <description>&lt;P&gt;Hello, I have a question about the use of the &lt;CODE&gt;foreach&lt;/CODE&gt; command. I have a good idea what the &lt;CODE&gt;foreach&lt;/CODE&gt; command can do for example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=summary source="summary_events_2" 
orig_source=$source$
ms_region=$region$
ms_level=$level$
| timechart span=5m  partial=f sum(count) as count
| timewrap d series=short
| rename s0 as Today
| foreach s*
     [eval d&amp;lt;&amp;lt;MATCHSTR&amp;gt;&amp;gt; = Today - &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I know that this will create new columns like &lt;CODE&gt;d1,d2,d3,d4,...&lt;/CODE&gt; that will contain the difference of &lt;CODE&gt;Today&lt;/CODE&gt; and &lt;CODE&gt;s*&lt;/CODE&gt; .&lt;/P&gt;

&lt;P&gt;Here is my dilemma: what if I do something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   index=summary source="summary_events_2" 
     orig_source=$source$
     ms_region=$region$
     ms_level=$level$
     | timechart span=5m  partial=f sum(count) as count by ms_level        (//note that there are 4 levels)
     | timewrap d series=short
     | rename *_s0 as *_Today
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This would give me columns like &lt;CODE&gt;ERROR_Today, WARNING_TODAY, ERROR_s1, ERROR_s2,WARNING_s1....&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Is there a way to achieve the same result as the first query using the &lt;CODE&gt;foreach&lt;/CODE&gt; command. I want to be able to create new columns like &lt;CODE&gt;ERROR_d1, ERROR_d2, WARNING_d1, WARNING_d2&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 16:26:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-new-columns-with-the-foreach-command/m-p/412472#M118920</guid>
      <dc:creator>kiamco</dc:creator>
      <dc:date>2018-10-09T16:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create new columns with the foreach command?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-new-columns-with-the-foreach-command/m-p/412473#M118921</link>
      <description>&lt;P&gt;You can use the &lt;CODE&gt;&amp;lt;&amp;lt;MATCHSEGn&amp;gt;&amp;gt;&lt;/CODE&gt; options to break up the names &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  | rename *_s0 as *_Today
  | foreach *_s*  [eval &amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;_d&amp;lt;&amp;lt;MATCHSEG2&amp;gt;&amp;gt; = &amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;_Today - &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you wanted, you could flip the field name order at the same time.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  | rename *_s0 as Today_*
  | foreach *_s*  [eval d&amp;lt;&amp;lt;MATCHSEG2&amp;gt;&amp;gt;_&amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt; = Today_&amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt; - &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt; | rename &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt; as  s&amp;lt;&amp;lt;MATCHSEG2&amp;gt;&amp;gt;_&amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt; ]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;HR /&gt;

&lt;P&gt;Here's some arbitrary run-anywhere test code for people to play with.  Run this for the preceding 6 minutes.  You do need access to the &lt;CODE&gt;_internal&lt;/CODE&gt; index.  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal group=*  name=* | eval myfan=mvrange(0,31,3) | mvexpand myfan | eval _time = _time + myfan + ( ( ( random() %1475 ) % 341 ) %60)
| where _time &amp;gt;= relative_time(now(),"-5m@m") AND  _time &amp;lt; relative_time(now(),"@m")
| timechart span=10s partial=f limit=10 count by name useother=f 
| where _time &amp;gt;= relative_time(now(),"-2m@m") AND  _time &amp;lt; relative_time(now(),"@m")
| fields - NULL
| timewrap min series=short 
| rename *_s0 as *_Today
| foreach *_s*  [eval &amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;_d&amp;lt;&amp;lt;MATCHSEG2&amp;gt;&amp;gt; = &amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;_Today - &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 10 Oct 2018 15:44:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-new-columns-with-the-foreach-command/m-p/412473#M118921</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2018-10-10T15:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: How do I create new columns with the foreach command?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-new-columns-with-the-foreach-command/m-p/412474#M118922</link>
      <description>&lt;P&gt;Sure, like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=summary source="summary_events_2" 
      orig_source=$source$
      ms_region=$region$
      ms_level=$level$
| timechart span=5m partial=f sum(count) AS count BY sourcetype
| timewrap d series=short 
| rename *s0 AS *Today 
| foreach *s* [ eval &amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;d&amp;lt;&amp;lt;MATCHSEG2&amp;gt;&amp;gt; = &amp;lt;&amp;lt;MATCHSEG1&amp;gt;&amp;gt;Today - &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 11 Feb 2019 10:20:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-create-new-columns-with-the-foreach-command/m-p/412474#M118922</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-02-11T10:20:53Z</dc:date>
    </item>
  </channel>
</rss>

