Knowledge Management

lookup fields cannot be calculated using eval

jyab6z
Path Finder

Hi,

I have problem with eval for those fields generated by lookup, here is my search:

my basic search | table DATE TimeInSec UserID Function Serie_nr prodClass prod_nr | lookup test.csv Product as prod_nr OUTPUT Product_class as prodClass_temp_csv, Development_stage as Serie_nr_csv | eval total_serie = Serie_nr + Serie_nr_csv | eval total_prodClass = prodClass + prodClass_temp_csv

But for some reason, total_serie field does not even show up in the Statistics and total_prodClass shows only the values of prodClass, not prodClass_temp_csv.

Any idea?

Tags (1)
0 Karma

somesoni2
Revered Legend

What type of values does your lookup table has for field Development_stage and Product_class? String or numbers? Did you check if your lookup table do have matching Product from base search?

0 Karma

jyab6z
Path Finder

Hi @somesoni2,

Development_stage and Product_class could contian both types, actually I wanna join those fields, not sum of those. I have checked the lookup as well, the matched results exist in the table.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...