Is it possible to execute a calculation during log file ingest based on two fields in the log file with the result of the calculation placed in a new field?
My Splunk admin states that is not possible, but seems too simple a function to be able to do.
Add EVAL statements to your props.conf file. See http://docs.splunk.com/Documentation/Splunk/6.1.2/Admin/Propsconf
Do note though, calculated fields are not calculated during log file ingest / at index time but rather at search time.
At index time you're stuck with regular expressions, which do not have the power to do maths.
Another link with steps to add eval (calculated fields) from UI and props.conf
http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/definecalcfields