Hi Mahesh,
Something like following using stats with eval should work and it is preferable to use rename instead of eval for renaming fields.
source="F:Splunk_Log Files*" status="Allow" | eval bytes=round(((recv_bytes)/1024),2) | eval Start=substr(dst_ip, 1, 3)| eval End=substr(dst_ip, 1, 3 )|stats sum(bytes) as File_Transfer sum(eval(if( Start>=1 AND End<=85,bytes,0))) as Infrastructure by src_ip| rename Infrastructure AS Infrastructure ." MB"| rename File_Transfer AS File_Transfer." MB"
Thanks,
Sanjay
... View more