Getting Data In

Calculations During Log File Ingest

notnavi
New Member

Is it possible to execute a calculation during log file ingest based on two fields in the log file with the result of the calculation placed in a new field?

My Splunk admin states that is not possible, but seems too simple a function to be able to do.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Add EVAL statements to your props.conf file. See http://docs.splunk.com/Documentation/Splunk/6.1.2/Admin/Propsconf

---
If this reply helps you, an upvote would be appreciated.
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Do note though, calculated fields are not calculated during log file ingest / at index time but rather at search time.

At index time you're stuck with regular expressions, which do not have the power to do maths.

0 Karma

somesoni2
Revered Legend

Another link with steps to add eval (calculated fields) from UI and props.conf

http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/definecalcfields

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!