Dashboards & Visualizations
Highlighted

using "eval" in a search form - results table not updating

Communicator

Hello,

I'm trying to get a form search to work where based on "group" I want an "eval" field called totalbytes to show up in a data table on my dashboard view. My search below works correctly from the search bar, but when I add as a form to a custom view, my result set does not show totalbytes.

Can someone help me to determine what's wrong?
Here's the search that works:

index=nc3sec sourcetype=syslog jav20023: | eval totalbytes = sent + rcvd | stats sum(totalbytes) by group

Here's my xml for the form:



<!-- define master search template; leave time unbounded so that the time input can be used -->
index=nc3sec group="$group$"



<!-- Define a radio button list, populated from a search. searchWhenChanged propagates any change in selection immediatly to the results. -->





Any

<![CDATA[index=nc3sec sourcetype=syslog jav20023: | eval totalbytes = sent + rcvd | stats sum(totalbytes) by group]]>

  <!-- add default TimePicker -->  
  <input type="time" />  

  <!-- show results in event viewer -->  
  <table>  
    <title>Total Bytes By Group</title>  
    <option name="count">50</option>  
  </table>  

Tags (1)
0 Karma
Highlighted

Re: using "eval" in a search form - results table not updating

Builder

I am not sure if this solve your problem. Could you try following search?

"sourcetype=syslog jav20023: | eval totalbytes = sent + rcvd | stats sum(totalbytes) AS total by group | table total group "

Your field "total_bytes" seems not appear just in your row table view. So, I think using table command will help this.

0 Karma