Splunk Search

Sum integer-named variables?

ctallarico20
Path Finder

Hi, so given a log including TwoHundred=5 it's pretty easy to make a timechart with a sum(TwoHundred) command. However, my logs are http responses, so they look like 200=5 and the sum(200) does not return results on the graph. Any idea of something that will tell splunk that the 200 is intended as a string?

Tags (2)
0 Karma
1 Solution

gfuente
Motivator

Hello

Try with: sum($200$)

Regards

View solution in original post

gfuente
Motivator

Hello

Try with: sum($200$)

Regards

ctallarico20
Path Finder

also if you don't mind me asking, what does $ do?

0 Karma

ctallarico20
Path Finder

hmm i really like the ideas you're coming up with but again that one produced no chart:/

0 Karma

gfuente
Motivator

Ok

And with a rename like:
...| rename $200$ as http_status | timechart sum(http_status)

??

ctallarico20
Path Finder

This is along the lines of what i was looking for, however just like sum(200), nothing is displayed on the timechart:( it turns up in the search if i look at the table though!

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...