Splunk Search

use * in floor

Splunkie1
Loves-to-Learn Lots

I have a field called position that contains integers and a token called position_select that is either a floating point number or a * (=all positions).

Now i want to search all positions that match position_select.

So i tried something like that:

index = index1

| eval position_search = floor($position_select$)

| where position = position_search

The problem is that you of course can't use * in floor.

Another problem is that | where position = * is impossible too.

However i cant use | search because | search position = position_search  does not work.

 

So the question is, is there any way to use something like floor()  on position_select?

 

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Set up your selection so that the value of the selection includes the where command, except in the case of *

    <input type="dropdown" token="position_select" searchWhenChanged="true">
      <label>Floored $position_select$</label>
      <choice value="">*</choice>
      <choice value="| where position=1">1.2</choice>
      <choice value="| where position=2">2.4</choice>
    </input>

Then just use the token in your search

index = index1
$position_select$
0 Karma

Splunkie1
Loves-to-Learn Lots

Thank you but, I get position_select dynamically from a search with up to 1000 results.

working through each position individually would be impractical.

Is there another way?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Have your dynamic search return two fields, one with the float in as the label field, and the other with a string of the where command.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...