Splunk Search

Is it possible for the chart command to not get executed unless cix is equal to the number 1?

New Member

I have the following search. What I would like is for the chart command to not get executed unless cix is equal to the number 1.
Is that possible? To have a conditional calculation?

| rename SMF70DTE as Date, SMF70TME as Time, SMF70SID as LPAR 
| eval IntervalTime=strftime(_time,"%H.%M")
| rex "SMF70CIX_\d{4}\":\"(?P<cix>[0-9.]+)\"" 
| rex "SMF70PDT_\d{4}\":\"(?P<pdt>[0-9.]+)\"" 
| chart sum(pdt) over IntervalTime by LPAR

Thanks, Bob

0 Karma

SplunkTrust
SplunkTrust

After rex number 1 and before chart, insert this line

| search cix=1 

It doesn't really matter if it's before or after rex number 2, but before rex number 2 is slightly more efficient.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!