Splunk Search

Is it possible for the chart command to not get executed unless cix is equal to the number 1?

bdh5574
New Member

I have the following search. What I would like is for the chart command to not get executed unless cix is equal to the number 1.
Is that possible? To have a conditional calculation?

| rename SMF70DTE as Date, SMF70TME as Time, SMF70SID as LPAR 
| eval IntervalTime=strftime(_time,"%H.%M")
| rex "SMF70CIX_\d{4}\":\"(?P<cix>[0-9.]+)\"" 
| rex "SMF70PDT_\d{4}\":\"(?P<pdt>[0-9.]+)\"" 
| chart sum(pdt) over IntervalTime by LPAR

Thanks, Bob

0 Karma

DalJeanis
Legend

After rex number 1 and before chart, insert this line

| search cix=1 

It doesn't really matter if it's before or after rex number 2, but before rex number 2 is slightly more efficient.

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...