The following previous splunk thread works fine:
| eval sensor = sensor + " %"
However, if the field name has a space, it does not work:
| eval "System Outlook" = "System Outlook" + " %"
System Outlook %
I'm assuming it needs some sort of backslash escaping? (I've tried a bunch of ways). I know I can just rename it without the space, but I want to keep the space.
When using field names with non standard characters, you need to use single quotes on the right hand side of the eval statement, i.e.
| eval "System Outlook" = 'System Outlook' + " %"
View solution in original post
Perfect, that worked!