I am trying to have a single value panel. The search for the same is given below:
index=* host="prodserver-*" source="/var/log/some.log" "something happened" | stats count
I need to add a fixed value of 1000 to the count value. I tried to use eval and add the value to count but its not working 😞
I can add two fixed values like the one given below, but using "count" is not working.
This works:
index=* host="prodserver-*" source="/var/log/some.log" "something happened" | eval totalCount = 1 + 1000 |stats max(totalCount)
This does not work:
index=* host="prodserver-*" source="/var/log/some.log" "something happened" | eval totalCount = count + 1000 |stats max(totalCount)
I am new to Splunk so please forgive me if this is a silly question :).
Try like this
index= host="prodserver-*" source="/var/log/some.log" "something happened" | stats count | eval count=count+1000
Try like this
index= host="prodserver-*" source="/var/log/some.log" "something happened" | stats count | eval count=count+1000
that worked, thank you
Hi @sunilkumarpk
Glad you found an answer through @somesoni2. Please don't forget to resolve the post by clicking "Accept" directly below his answer. Thanks!
Patrick