Splunk Search

Why Splunk is telling me that my eval expression is malformed?

tcmarquesi
Explorer

I'm trying to evaluate the normal distribuiton's PDF into my search as follows:

... | eval prob=(1/sqrt(2*pi()*sigma^2))*exp(-((x-mi)^2)/(2*sigma^2))

And I'm getting this error message:

Error in 'eval' command: The expression is malformed. Expected ).

What am I doing wrong? I tested the expression on Excel and it works fine...

Tags (2)
0 Karma
1 Solution

sundareshr
Legend

I haven't tested this, but at first glance, it could be because of the the power of function. Change all occurences of sigma^2 to pow(sigma, 2). So your formula s/b written like this

(1/sqrt(2*pi()*pow(sigma,2)))*exp(-(pow((x-mi),2))/(2*pow(sigma, 2)))

View solution in original post

sundareshr
Legend

I haven't tested this, but at first glance, it could be because of the the power of function. Change all occurences of sigma^2 to pow(sigma, 2). So your formula s/b written like this

(1/sqrt(2*pi()*pow(sigma,2)))*exp(-(pow((x-mi),2))/(2*pow(sigma, 2)))

tcmarquesi
Explorer

Thank you!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...