Splunk Search

How to convert a number to String?

gokikrishnan
New Member

Can somebody please help me in converting a number back to string?

Tags (1)
0 Karma

renjith_nair
Legend

@gokikrishnan,

eval num_field = tostring(num_field)

Reference : tostring

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

gokikrishnan
New Member

I did the following
eval num_field = tostring(num_field)|stats num_field by Field.
It was working till tostring conversion. Throwing error if I use the stats command. The error as follows
Error in 'stats' command: The argument 'Field' is invalid.

0 Karma

renjith_nair
Legend

for using stats you need an aggregate function like , sum,max,min etc

If you could tell us your exact requirement, that might help

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

niketn
Legend

@gokikrishnan as stated by @renjith.nair the issue seems to be with your stats command rather than string conversion. Seems like you will not need string conversion in the first place. For the community to assist you better with your query it would be nice if you provide what is the kind of data you have and what is the output you need. You should check out Statistical aggregating functions to understand them better: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonStatsFunctions#Supported_f...

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...