Splunk Search

How to apply eval to a field which contains "."?

bollam
Path Finder

Hello,

I have got a field name "test_time.space_used" in the events and I need to perform arithmetic operations to this field.

| eval test_time.space_used  =  test_time.space_used/1024/1024

But this is not producing any results. Can you assist me on this?
Thanks in advance

Tags (1)
0 Karma
1 Solution

renjith_nair
Legend

@bollam ,

Try

| eval test_time.space_used = 'test_time.space_used'/1024/1024
---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

renjith_nair
Legend

@bollam ,

Try

| eval test_time.space_used = 'test_time.space_used'/1024/1024
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

bollam
Path Finder

@renjith.nair, Thanks !! It worked

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...