Most likely because Splunk doesn't consider the fields to be numerical. By default Splunk will consider "." to be a decimal sign but not ",". Short fix would be to replace "," with "." in your numbers.
This should do it -
your base search
| eval basavalue="97,56"
| rex field=basavalue mode=sed "s/,/./g"
Most likely because Splunk doesn't consider the fields to be numerical. By default Splunk will consider "." to be a decimal sign but not ",". Short fix would be to replace "," with "." in your numbers.
no way to converto those "string" into values?!?
I have same issue. Is there any easy fix?