<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: search string in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/search-string/m-p/85468#M21834</link>
    <description>&lt;P&gt;Till the below portion it is working fine..&lt;/P&gt;

&lt;P&gt;index=os source=df |multikv fields Filesystem Avail UsePct | search Filesystem=/dev/mapper/system-root &lt;/P&gt;

&lt;P&gt;then when I am adding "stats avg(Avail) as availDisk by host" it is not fetching any data...where as if I add "stats values(Avail) as availDisk by host" then the data is coming...&lt;/P&gt;

&lt;P&gt;Any thought!!!&lt;/P&gt;</description>
    <pubDate>Fri, 11 Jan 2013 20:08:41 GMT</pubDate>
    <dc:creator>Splunk_U</dc:creator>
    <dc:date>2013-01-11T20:08:41Z</dc:date>
    <item>
      <title>search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-string/m-p/85464#M21830</link>
      <description>&lt;P&gt;Is there any thing wrong with the below search string?????&lt;/P&gt;

&lt;P&gt;index=os source=df |multikv fields Filesystem Avail UsePct | search Filesystem=/dev/mapper/system-root | eval availPct=(100-UsePct) | stats avg(Avail) as availDisk avg(availPct) as UsePct by host&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 18:17:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-string/m-p/85464#M21830</guid>
      <dc:creator>Splunk_U</dc:creator>
      <dc:date>2013-01-11T18:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-string/m-p/85465#M21831</link>
      <description>&lt;P&gt;I assume there's a reason for asking? What results are you currently getting?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 18:51:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-string/m-p/85465#M21831</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-01-11T18:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-string/m-p/85466#M21832</link>
      <description>&lt;P&gt;I am getting no result...but it should provide me the avg available disk info and and avg available percentage..Am I missing something in syntax???&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 18:53:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-string/m-p/85466#M21832</guid>
      <dc:creator>Splunk_U</dc:creator>
      <dc:date>2013-01-11T18:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-string/m-p/85467#M21833</link>
      <description>&lt;P&gt;It usually makes sense to break down your search and track when you are getting data and then where you aren't getting what you expect.  Start with the beginning and then add additional commands one by one to see where the search is breaking down.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 20:04:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-string/m-p/85467#M21833</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2013-01-11T20:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-string/m-p/85468#M21834</link>
      <description>&lt;P&gt;Till the below portion it is working fine..&lt;/P&gt;

&lt;P&gt;index=os source=df |multikv fields Filesystem Avail UsePct | search Filesystem=/dev/mapper/system-root &lt;/P&gt;

&lt;P&gt;then when I am adding "stats avg(Avail) as availDisk by host" it is not fetching any data...where as if I add "stats values(Avail) as availDisk by host" then the data is coming...&lt;/P&gt;

&lt;P&gt;Any thought!!!&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 20:08:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-string/m-p/85468#M21834</guid>
      <dc:creator>Splunk_U</dc:creator>
      <dc:date>2013-01-11T20:08:41Z</dc:date>
    </item>
    <item>
      <title>Re: search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-string/m-p/85469#M21835</link>
      <description>&lt;P&gt;What format are the values for Avail in? If avg() doesn't return anything even though Avail has values, it indicates that the Avail values aren't something that avg() can treat as numbers.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 20:22:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-string/m-p/85469#M21835</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-01-11T20:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-string/m-p/85470#M21836</link>
      <description>&lt;P&gt;Verify is UsePct is a string or a number.&lt;BR /&gt;
use &lt;CODE&gt;| convert num(UsePct)&lt;/CODE&gt; if needed&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jan 2013 02:39:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-string/m-p/85470#M21836</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-01-12T02:39:18Z</dc:date>
    </item>
  </channel>
</rss>

