Dashboards & Visualizations

Error in 'where' command becuase of ','

Questioner
Path Finder

When I use my code, I can see this error.

" Error in 'where' command : The operator at ',127.542 - 0.001' is invalid.

The problem code is this.

| where time >= $max_value$ - 0.001

 When I print "max_value"  at title, I can see that value is "315,127.542"

 

I think the reason this problem occurred is  ',' at the max_value. 

How could I remove ',' at the max_value?

And If it was not the problem, How could I solve this?

Tags (2)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

You can use an <eval> statement for your drilldown instead of <set>

<eval token="max_value">replace($click.value$, ",", "")</eval>

 

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Technically you could do the following to fix the symptoms

| where time >= tonmumber(replace($max_value$, ",", "")) - 0.001

but you are better off finding the source of the token, as @PickleRick says, and make sure it contains something suitable to perform calculations with if that's how you intend to use it.

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK. The question is where are you getting this token from. Because apparently it's a formatted number which indeed might cause the error.

0 Karma

Questioner
Path Finder

OH..! I get this token at <single> block.

The code for this <signle> block looks like this.

<single>
<title>Max time</title>
<search>
<query>index=idx_prd_analysis sourcetype="type:prd_analysis:delay_time" corp="delay"
| where (plane_type==1) OR (plane_type==2)
| eval total_time = round(takeOff_time - boarding_time, 3)
| stats MAX(total_time)</query>
<earliest>$_time.earliest$</earliest>
<latest>$_time.latest$</latest>
</search>
<option name="colorMode">block</option>
<option name="drilldown">all</option>
<option name="height">154</option>
<option name="numberPrecision">0.000</option>
<option name="rangeValues">[500]</option>
<option name="refresh.display">progressbar</option>
<option name="unitPosition">before</option>
<drilldown>
<set token="max_value">$click.value$</set>
</drilldown>
</single> 

 

Are there any solution to send max_value as normal format not origin? (Not 123,456 -> Wnat 123456)

0 Karma

bowesmana
SplunkTrust
SplunkTrust

You can use an <eval> statement for your drilldown instead of <set>

<eval token="max_value">replace($click.value$, ",", "")</eval>

 

0 Karma

Questioner
Path Finder

It work!!!
Thank you for your help 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...