Splunk Search

How to use fields from two csv files in a search for an arithmetic calculation to create a new field?

Path Finder

HI,

I have two files, test1.csv and test2.csv.
I want to do some arithmetic calculation involving fields from both files test1.csv and test2.csv.
Also, i want to use only september month data from test1.csv.Please let me know how to involve both files in a single query to cter to my requirement.

test1.csv has fields ->name,start time,end time,totaltime,datemonth
test2.csv has fields->name,NoofPerson,lost_time

What i require is, if datemonth=september from test1.csv and 'name' from test1.csv ='name' from test2.csv,then A=totaltimeNoofPersonlost_time, where 'A' is a new field i want to create.

Tags (3)
0 Karma

Legend

How about

| inputlookup test1.csv | search date_month="september" | join name [inputlookup test2.csv] | eval A=total_time*No_of_Person*lost_time

Legend

Please add more information - exactly what kind of calculations, and what your csv files look like.

0 Karma

Path Finder

test1.csv has fields ->name,start time,end time,totaltime,datemonth
test2.csv has fields->name,NoofPerson,lost_time

What i require is, if datemonth=september from test1.csv and 'name' from test1.csv ='name' from test2.csv,then A=totaltimeNoofPersonlost_time, where 'A' is a new field i want to create.

0 Karma