Splunk Search
Highlighted

Eval Question for Table

Engager

Using the table below I have the following query table ServerName,ServerTotalPhysicalMemory,ServerCores,ServerNumberofProcessors,ServerDomain,ServerIsVirtual,ServerLastScanDate,ServerSerialNumber,ServerSite,AssociatedAppliationProductName,AssociatedOperatingSystem,time | stats count() | transpose
I would like to divide each value by count(Server_Name) is there a way to do that using the EVAL function?
alt text

Tags (1)
0 Karma
Highlighted

Re: Eval Question for Table

SplunkTrust
SplunkTrust

Try something like this

table Server_Name,Server_TotalPhysicalMemory,Server_Cores, Server_NumberofProcessors, Server_Domain,Server_IsVirtual,Server_LastScanDate,Server_SerialNumber, Server_Site, Associated_AppliationProductName,Associated_OperatingSystem,_time | stats count(*) as count_*  | eval divider=count_Server_Name | untable divider column value | eval value=value/divider | fields - divider

View solution in original post

0 Karma