Splunk Search

How to implement math calculations?

asarran
Path Finder

Hey, Fellow Splunkers

I'm curious to know if it's possible to preform math calculations on a set of "refined" data; for example:

Let's say I extracted a field that presents the values of a gigabit into megabit? meaning I have 5 gig it would then be converted into 5120.
so ideally I would like to take an entire field of data and multiple it by 1024? and have that information be presented when I call the field into a table?

intial
5gb
4gb
3gb

output
5120mb
4096mb
3072mb

Tags (1)
0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

Eval is your friend...

  | eval output=initial*1024

Or in this case you'd have to get the number first with Rex

  | rex field=initial "(?<gb>\d+)" | eval output=gb*1024

View solution in original post

jkat54
SplunkTrust
SplunkTrust

Eval is your friend...

  | eval output=initial*1024

Or in this case you'd have to get the number first with Rex

  | rex field=initial "(?<gb>\d+)" | eval output=gb*1024

asarran
Path Finder

hey, thx

the answer was correct, however it was off by a bit had to enter another \d +\d for other decimal values.

I greatly appreciate your response,

thank you, asarran

0 Karma

MuS
Legend

Hi asarran,

take a look at the docs about the convert command http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Convert and its option memk().
But to answer your question, math calculation can be made with the eval command http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Eval using the Arithmetic operators.

Hope this helps ...

cheers, MuS

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...