Hello SMEs,
Seeking support to eval new field from two already being extracted one.
I have bytes_received & bytes_sent fields. Wanted to have one more field (total_bytes) which will have addition of both
eval total_bytes = bytes_received + bytes_sent
Please suggest
Hope you want to create a new field at search time instead of writing that above mentioned line in search every time.
if yes follow below:
Create props.conf in local directory in any application under apps directory of search head and add below:
[sourcetype]
EVAL-total_bytes = bytes_received+bytes_sent
Note: you should replace sourcetype with the source type for which you want to have new field.
Hope you want to create a new field at search time instead of writing that above mentioned line in search every time.
if yes follow below:
Create props.conf in local directory in any application under apps directory of search head and add below:
[sourcetype]
EVAL-total_bytes = bytes_received+bytes_sent
Note: you should replace sourcetype with the source type for which you want to have new field.