Getting Data In

Calculations During Log File Ingest

New Member

Is it possible to execute a calculation during log file ingest based on two fields in the log file with the result of the calculation placed in a new field?

My Splunk admin states that is not possible, but seems too simple a function to be able to do.

Tags (1)
0 Karma


Add EVAL statements to your props.conf file. See

If this reply helps you, an upvote would be appreciated.
0 Karma


Do note though, calculated fields are not calculated during log file ingest / at index time but rather at search time.

At index time you're stuck with regular expressions, which do not have the power to do maths.

0 Karma

Revered Legend

Another link with steps to add eval (calculated fields) from UI and props.conf

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!