Knowledge Management

Perform calculations on a count of EventTypes

New Member

I have having trouble performing basic calculations using Eval. I can do '2*2' but I cannot do this with a count of eventtype.

I have a search running, to total EventTypes that I created.

sourcetype=csv | timechart span="1d" , count(eval(eventtype="OC-Main Player_Loaded")) AS OC-Main-player-loaded, count(eval(eventtype="OC-Main User_Interacted")) AS OC-Main-User_Interacted

This creates a table, showing the time, and then a count of the EventTypes (in this case "OC-Main PlayerLoaded" and "OC-Main UserInteracted").

alt text

I want to create a 4th column, that would give me a calculation, based on these counts. What I want is a %, but at the moment I can't get anything to work.

If I add a simple Eval at the end, the result shows. eg... | eval ocper=(2*2) shows as 4
However, if I try and use the AS event names (eg: OC-Main-player-loaded) nothing shows.

My guess is, OC-Main-player-loaded is just the name of the table column, and splunk has no concept of what I am trying to multiply. I assume I need to specify that the count should be some sort of field that can be multiplied. How do I do this?

thanks in advanced.

Tags (2)
0 Karma


I would firstly try simplifying the names you are using the timechart command, and use something simple like:

OC-Main-player-loaded --> loaded

Then pipe to your eval command and use the simplified field labels in your calculation. I have had issues in the past with processing certain field names.

I would then pipe to rename to change the simplified field labels to something more legible.

Hope this helps.


No problem, to close this question off, can you mark the answer as accepted with the empty tick beside the answer.


0 Karma

New Member

Ok, that works. thank you very much. It's probably something I should have tried about 4 hours ago. Instead I have been reading docs, trying examples, looking in the wiki. You live and learn! cheers!

0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...