Splunk Search

How to add Currency Symbol ($ dollar sign) to a column with numbers?

tdunphy_
Explorer

Hi all,

I have a column in splunk that I want to use to show totals. I would like for the dollar sign ($) to appear before the numbers in the totals column.

Here's my query:

index=prd_aws_billing (source="/*2017-12.csv") LinkedAccountId="123456678" ProductName="Amazon Elastic Compute Cloud" | stats sum(UnBlendedCost) AS Cost by ResourceId,UsageType,user_Name,user_Engagement

How do I get the numbers in the UnBlendedCost column to appear with a dollar sign in front of them?

Thanks

0 Karma
1 Solution

livehybrid
Contributor

Hi,
Try this:

index=prd_aws_billing (source="/*2017-12.csv") LinkedAccountId="123456678" ProductName="Amazon Elastic Compute Cloud" | stats sum(UnBlendedCost) AS Cost by ResourceId,UsageType,user_Name,user_Engagement | fieldformat Cost="$".tostring(Cost)

View solution in original post

livehybrid
Contributor

Hi,
Try this:

index=prd_aws_billing (source="/*2017-12.csv") LinkedAccountId="123456678" ProductName="Amazon Elastic Compute Cloud" | stats sum(UnBlendedCost) AS Cost by ResourceId,UsageType,user_Name,user_Engagement | fieldformat Cost="$".tostring(Cost)

tdunphy_
Explorer

That's perfect. Thank you!

0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...