Splunk Search

How to Make operations between two columns

nalagito
Loves-to-Learn Lots

Hello, I have this query:

 

 

| mstats avg(_value) as packets WHERE index=metrics_index sourcetype=network_metrics (metric_name=*.out) ((metric_name="InterfaceEthernetA.*" OR metric_name="InterfaceEthernetB.*") AND (host="hostA" OR host="hostB")) span=1m by metric_name,host 
| rex field=metric_name ".*InterfaceEthernet(?<mn>\d_\d*)"
| eval kbits=packets*8/1000
| timechart span=30m sum(kbits) by mn

 

 

 

It returns this results:

 

img.jpeg

 

From those results, I would like to make operations generating another column with those results...

 

For example: (ColumnA - ColumnB) / ColumnA * 100

 

How could I do that?

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @nalagito,

if the values of ColumnA and ColumnB are fixed, you can use the eval command to make the calculation you need.

If instead they aren't fixed, is much more complicated.

Ciao.

Giuseppe

0 Karma

nalagito
Loves-to-Learn Lots

@gcusello 

Could you please give me an example? What do you mean with "fixed"?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @nalagito,

if the values of mn are always:

  • my_mn1,
  • my_mn2.

in this case you can make operations using my_mn1 and my_mn2 as column name.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...