Splunk Search

Sum integer-named variables?

ctallarico20
Path Finder

Hi, so given a log including TwoHundred=5 it's pretty easy to make a timechart with a sum(TwoHundred) command. However, my logs are http responses, so they look like 200=5 and the sum(200) does not return results on the graph. Any idea of something that will tell splunk that the 200 is intended as a string?

Tags (2)
0 Karma
1 Solution

gfuente
Motivator

Hello

Try with: sum($200$)

Regards

View solution in original post

gfuente
Motivator

Hello

Try with: sum($200$)

Regards

ctallarico20
Path Finder

also if you don't mind me asking, what does $ do?

0 Karma

ctallarico20
Path Finder

hmm i really like the ideas you're coming up with but again that one produced no chart:/

0 Karma

gfuente
Motivator

Ok

And with a rename like:
...| rename $200$ as http_status | timechart sum(http_status)

??

ctallarico20
Path Finder

This is along the lines of what i was looking for, however just like sum(200), nothing is displayed on the timechart:( it turns up in the search if i look at the table though!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...