I am new to Splunk, and I need to perform arithmetic on some multi-field values. What is the best way to do this? Here is an example of an event (where the "stuff" field is an array containing any number of key-value pairs with "A" and "B"):
event1 {
name: foo
stuff: [
{
A: 10
B: 220.0
}
{
A: 2
B: 50.0
}
]
}
event2 {
name: foo
stuff: [
{
A: 2
B: 100.0
}
]
}
Here is the search I am using:
<my search>
| mvexpand stuff{}
| rename stuff{}.* as *
| eval test=B/A
| table _time A B test
However, test is empty whenever there is more than 1 "stuff" in my event. In the example above: test=null, null, 50
My goal is to calculate "test" so that: test=22, 25, 50
... View more