I have a non numerical field (text), and I want to create an enum field.
Meaning that I will have a new field with numerical values that match the text values of the original field.
Thanks 🙂
| makeresults | eval _raw="Id Message ...
1 Success ...
2 Fail ...
3 Error ...
4 Success" | multikv forceheader=1
| table Id Message
| eventstats values(Message) as enum_key
| eval enum=mvfind(enum_key,Message)
| table Id Message enum
| makeresults | eval _raw="Id Message ...
1 Success ...
2 Fail ...
3 Error ...
4 Success" | multikv forceheader=1
| table Id Message
| eventstats values(Message) as enum_key
| eval enum=mvfind(enum_key,Message)
| table Id Message enum
Can you please explain more with example like sample value of non numerical field and expected results from that field.
KV
Sure.
Assume the following table
Id | Message | ... |
1 | Success | ... |
2 | Fail | ... |
3 | Error | ... |
4 | Success | ... |
I want to get another field that will automatically assign a number to each message. (This number can be a random number or serial, what is important for me is that the numerical values from the new field correlate to the "message" field.
Id | Message | (New Field) | ... |
1 | Success | 1 | ... |
2 | Fail | 2 | ... |
3 | Error | 3 | ... |
4 | Success | 1 | ... |
Can you please try this?
YOUR_SEARCH
| eval anotherField=case(Message="Success",1,Message="Fail",2,Message="Error",3)
My Sample Search :
| makeresults | eval _raw="Id Message ...
1 Success ...
2 Fail ...
3 Error ...
4 Success" | multikv forceheader=1
| table Id Message | eval anotherField=case(Message="Success",1,Message="Fail",2,Message="Error",3)
Thanks
KV
▄︻̷̿┻̿═━一 ?
If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.
Hi KV,
Actually I am looking to automatically assign the number.
I have around 100 values of "message" therefore a "case when" type solution does not work here.
The number that is assigned can be random, what is important is to be able to correlate between logs according to this new number field.
Is there a solution for this?
Thanks!