Hi!
I'm indexing XML data containing free memory values and get a nice stats table, but not be able to show that as a graph because Splunk interprets memory values as strings.
My event example is attached.
I tried to convert string to numbers, but didn't succeed.
sourcetype=DCM_MEAS_XML | rename Measurement.lcp0_shp as lcp0_shp | eval num=if(isnum(lcp0_shp),"yes","no") | eval str=if(isstr(lcp0_shp),"yes","no") | Convert num(lcp0_shp) as number | eval converted=if(isnum(number),"yes","no") | stats values(num) values(str) values(converted) values(number) by _time
This gave me following output:
_time values(num) values(str )values(converted) values(number)
2016-02-22 19:41:28.359 no yes no 2976716
Sample event:
... View more