Splunk Search

Sum integer-named variables?

ctallarico20
Path Finder

Hi, so given a log including TwoHundred=5 it's pretty easy to make a timechart with a sum(TwoHundred) command. However, my logs are http responses, so they look like 200=5 and the sum(200) does not return results on the graph. Any idea of something that will tell splunk that the 200 is intended as a string?

Tags (2)
0 Karma
1 Solution

gfuente
Motivator

Hello

Try with: sum($200$)

Regards

View solution in original post

gfuente
Motivator

Hello

Try with: sum($200$)

Regards

ctallarico20
Path Finder

also if you don't mind me asking, what does $ do?

0 Karma

ctallarico20
Path Finder

hmm i really like the ideas you're coming up with but again that one produced no chart:/

0 Karma

gfuente
Motivator

Ok

And with a rename like:
...| rename $200$ as http_status | timechart sum(http_status)

??

ctallarico20
Path Finder

This is along the lines of what i was looking for, however just like sum(200), nothing is displayed on the timechart:( it turns up in the search if i look at the table though!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...