Splunk Search

multiple field conversions in a search eg kb to Mb

Conradj
Path Finder

Hi,

I have multiple fields returned in a search that I to plot as separate lines on a line graph. however, both fields are by default provided in bytes. I want to convert both in megabytes for the plot

Data might be for example...
time=12:00:00, memUsage=194433567, memPeak=1949456694

i can use | eval current=(memUsage/1024/1024)

But how do I convert the second? before going onto define the chart? (I am sure that its something very simple, but so far it has escaped me)

Cheers,

C.

Tags (3)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Something like:

<search_term> | eval current=(memUsage/1024/1024) | eval peak=memPeak/1048576 | timechart span=1h avg(current), max(peak)

?

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

Something like:

<search_term> | eval current=(memUsage/1024/1024) | eval peak=memPeak/1048576 | timechart span=1h avg(current), max(peak)

?

Conradj
Path Finder

(argh) Thank you 🙂

My error was in defining the chart to use two fields, not the conversion.

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...