Getting Data In
Highlighted

Calculations During Log File Ingest

New Member

Is it possible to execute a calculation during log file ingest based on two fields in the log file with the result of the calculation placed in a new field?

My Splunk admin states that is not possible, but seems too simple a function to be able to do.

Tags (1)
0 Karma
Highlighted

Re: Calculations During Log File Ingest

SplunkTrust
SplunkTrust

Add EVAL statements to your props.conf file. See http://docs.splunk.com/Documentation/Splunk/6.1.2/Admin/Propsconf

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: Calculations During Log File Ingest

SplunkTrust
SplunkTrust

Another link with steps to add eval (calculated fields) from UI and props.conf

http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/definecalcfields

0 Karma
Highlighted

Re: Calculations During Log File Ingest

SplunkTrust
SplunkTrust

Do note though, calculated fields are not calculated during log file ingest / at index time but rather at search time.

At index time you're stuck with regular expressions, which do not have the power to do maths.

0 Karma