Splunk Search

How to implement math calculations?

asarran
Path Finder

Hey, Fellow Splunkers

I'm curious to know if it's possible to preform math calculations on a set of "refined" data; for example:

Let's say I extracted a field that presents the values of a gigabit into megabit? meaning I have 5 gig it would then be converted into 5120.
so ideally I would like to take an entire field of data and multiple it by 1024? and have that information be presented when I call the field into a table?

intial
5gb
4gb
3gb

output
5120mb
4096mb
3072mb

Tags (1)
0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

Eval is your friend...

  | eval output=initial*1024

Or in this case you'd have to get the number first with Rex

  | rex field=initial "(?<gb>\d+)" | eval output=gb*1024

View solution in original post

jkat54
SplunkTrust
SplunkTrust

Eval is your friend...

  | eval output=initial*1024

Or in this case you'd have to get the number first with Rex

  | rex field=initial "(?<gb>\d+)" | eval output=gb*1024

asarran
Path Finder

hey, thx

the answer was correct, however it was off by a bit had to enter another \d +\d for other decimal values.

I greatly appreciate your response,

thank you, asarran

0 Karma

MuS
Legend

Hi asarran,

take a look at the docs about the convert command http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Convert and its option memk().
But to answer your question, math calculation can be made with the eval command http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Eval using the Arithmetic operators.

Hope this helps ...

cheers, MuS

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...