Dashboards & Visualizations

How to convert E10 notations to number?

aditsss
Motivator

Hi Team,

I am using below query to get my total closing balance

index="abc*" sourcetype=600000304_gg_abs_ipc2 " AssociationProcessor - compareTransformStatsData : statisticData: StatisticData" source="/amex/app/gfp-settlement-transform/logs/gfp-settlement-transform.log" |rex " AssociationProcessor - compareTransformStatsData : statisticData: StatisticData totalClosingBal=(?<totalClosingBal>)"|table _time  totalClosingBal| sort _time

I am getting current result as below:

7.71727634934E10

I want this E10 to be in actual numbers which can be done by below logic:

7.71727634934 × 1010

Can someone guide me how can I do this in splunk query.

Labels (2)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Assuming you have extracted the closing balance to the totalClosingBal field, you could try this

| eval bal=tonumber(mvindex(split(totalClosingBal,"E"),0)) * pow(10,tonumber(mvindex(split(totalClosingBal,"E"),1)))

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Assuming you have extracted the closing balance to the totalClosingBal field, you could try this

| eval bal=tonumber(mvindex(split(totalClosingBal,"E"),0)) * pow(10,tonumber(mvindex(split(totalClosingBal,"E"),1)))
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...