Splunk Search

How to Make operations between two columns

nalagito
Loves-to-Learn Lots

Hello, I have this query:

 

 

| mstats avg(_value) as packets WHERE index=metrics_index sourcetype=network_metrics (metric_name=*.out) ((metric_name="InterfaceEthernetA.*" OR metric_name="InterfaceEthernetB.*") AND (host="hostA" OR host="hostB")) span=1m by metric_name,host 
| rex field=metric_name ".*InterfaceEthernet(?<mn>\d_\d*)"
| eval kbits=packets*8/1000
| timechart span=30m sum(kbits) by mn

 

 

 

It returns this results:

 

img.jpeg

 

From those results, I would like to make operations generating another column with those results...

 

For example: (ColumnA - ColumnB) / ColumnA * 100

 

How could I do that?

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @nalagito,

if the values of ColumnA and ColumnB are fixed, you can use the eval command to make the calculation you need.

If instead they aren't fixed, is much more complicated.

Ciao.

Giuseppe

0 Karma

nalagito
Loves-to-Learn Lots

@gcusello 

Could you please give me an example? What do you mean with "fixed"?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @nalagito,

if the values of mn are always:

  • my_mn1,
  • my_mn2.

in this case you can make operations using my_mn1 and my_mn2 as column name.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...