Splunk Search

## Field Extraction And Evaluation

Observer

From the screenshot, i would like to achieve the below;

LCU04 = 500 x 00000
LCU03 = 500 x 01985
LCU02 = 500 x 01985
LCU01 = 500 x 01985

Then, LCU = (LCU04 + LCU03 + LCU02 + LCU01)

Thank you.

Tags (1)
1 Solution
Esteemed Legend

Like this:

``````| makeresults
| eval raw="2019-12-04 11:31:42.027 8 ResourceMgr   ATM 11:31:42 LCU Lcu04 500   00 00000   {journal}:::2019-12-04 11:31:42.024 8 ResourceMgr   ATM 11:31:42 LCU Lcu03 500   01 01985   {journal}:::2019-12-04 11:31:42.020 8 ResourceMgr   ATM 11:31:42 LCU Lcu02 500   01 01985   {journal}:::2019-12-04 11:31:42.017 8 ResourceMgr   ATM 11:31:42 LCU Lcu01 500   00 01985   {journal}"
| makemv delim=":::" raw
| mvexpand raw
| rename raw AS _raw
| eval _time = strptime(_raw, "%Y-%m-%d %H:%M:%S.%3N")
| sort 0 - _time

| rename COMMENT AS "Everything above generates sample event data; everything below is your solution"

| rex "LCU\s+(?<LCU_key>\S+)\s+(?<LCU_base>\d+)\s+(?<LCU_stage>\d+)\s+(?<LCU_multiplier>\d+)"
| eval {LCU_key} = LCU_base * LCU_multiplier
| filldown Lcu*
| eval LCU_total = Lcu01 + Lcu02 + Lcu03 + Lcu04
| where isnotnull(LCU_total)
| table LCU_total *
``````
Esteemed Legend

Like this:

``````| makeresults
| eval raw="2019-12-04 11:31:42.027 8 ResourceMgr   ATM 11:31:42 LCU Lcu04 500   00 00000   {journal}:::2019-12-04 11:31:42.024 8 ResourceMgr   ATM 11:31:42 LCU Lcu03 500   01 01985   {journal}:::2019-12-04 11:31:42.020 8 ResourceMgr   ATM 11:31:42 LCU Lcu02 500   01 01985   {journal}:::2019-12-04 11:31:42.017 8 ResourceMgr   ATM 11:31:42 LCU Lcu01 500   00 01985   {journal}"
| makemv delim=":::" raw
| mvexpand raw
| rename raw AS _raw
| eval _time = strptime(_raw, "%Y-%m-%d %H:%M:%S.%3N")
| sort 0 - _time

| rename COMMENT AS "Everything above generates sample event data; everything below is your solution"

| rex "LCU\s+(?<LCU_key>\S+)\s+(?<LCU_base>\d+)\s+(?<LCU_stage>\d+)\s+(?<LCU_multiplier>\d+)"
| eval {LCU_key} = LCU_base * LCU_multiplier
| filldown Lcu*
| eval LCU_total = Lcu01 + Lcu02 + Lcu03 + Lcu04
| where isnotnull(LCU_total)
| table LCU_total *
``````
Esteemed Legend

NEVER post images without also posting the text, otherwise WE have to type it in to help you.

Observer

Thank you. This helped.

Get Updates on the Splunk Community!

#### Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

#### Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

#### Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...