I am trying to have a single value panel. The search for the same is given below:
index=* host="prodserver-*" source="/var/log/some.log" "something happened" | stats count
I need to add a fixed value of 1000 to the count value. I tried to use eval and add the value to count but its not working 😞
I can add two fixed values like the one given below, but using "count" is not working.
This works:
index=* host="prodserver-*" source="/var/log/some.log" "something happened" | eval totalCount = 1 + 1000 |stats max(totalCount)
This does not work:
index=* host="prodserver-*" source="/var/log/some.log" "something happened" | eval totalCount = count + 1000 |stats max(totalCount)
I am new to Splunk so please forgive me if this is a silly question :).
... View more