This question is specific to the new Pivot functionality in Splunk 6.
I have built up my data model, defined all the attributes and am ready to crunch my data.
However, I have a field/attribute (notional) that is a numeric field with comma formatting (ex. 1,000,000).
What is the process for eliminating the comma so that I can properly define it as a number?
I understand how to do this in regular search but cant figure out the secret sauce for pivot.
Thanks
In the data model editor, you should be able to define an Eval attribute and do whatever you would do in regular search.
You are correct in a very general way.
Following:
http://answers.splunk.com/answers/36792/how-to-sum-numbers-with-commas
Using rex: "(?
The result was empty.
Using rex: setting field to notional
"(?
Caused a parse error in "//g"
Using eval: setting field to stripped_notional and then the eval expression: replace(notional, ",", "")
finally worked.