Hi to Everyone,
My question is ,i think, quite simple but i haven't found yet solution ^^ (i'm still quite new to Splunk!)
Let's say i have various field indexed, one contains the Data Unity and others values and so on.
I want to have only one kind of commands to generate all mycharts, currently the command is:
Without converting bytes to megabytes:
index="my_index" sourcetype="my_source" $hostname$ $monitor$ $monitor_label$ | timechart span=1h limit=10 max(value) by monitor_label
Converting bytes to megabytes:
index="my_index" sourcetype="my_source" $hostname$ $monitor$ $monitor_label$ | timechart span=1h eval(max(value)/1024/1024) by monitor_label
My goal is to have the same command for both cases including the condition where "data_unity" fields would contains "b/s" --> initiate conversion, otherwise let the data as normal.
Thank your very much for you help, as i am introducing Splunk into my company, getting the better result is my goal.
... | eval value=if(match(value,"b/s"),value/1024/1024,value) | ...
So what we're doing here is checking if the value contains "b/s", if it does we return value/1024/1024, otherwise we return the original value.
It will also match "Mb/s", so you might need to deal with that too, it could be as simple as changing the "match" to " b/s" (with a leading space).