Splunk Search

How to typecast an integer as a string literal

jcbrendsel
Path Finder

Is there any way to explicitly typecast a number in Splunk so that it is interpreted as a string literal rather than as a number?

IE, I want '64' to be interpreted as a string rather than as an integer.

Is this possible?

Tags (1)
1 Solution

araitz
Splunk Employee
Splunk Employee

Assuming the number is the value of an extracted field:

... | eval your_field = tostring(your_field)

This and other uses of eval can be found in the search reference:

http://www.splunk.com/base/Documentation/latest/SearchReference/CommonEvalFunctions

View solution in original post

araitz
Splunk Employee
Splunk Employee

Assuming the number is the value of an extracted field:

... | eval your_field = tostring(your_field)

This and other uses of eval can be found in the search reference:

http://www.splunk.com/base/Documentation/latest/SearchReference/CommonEvalFunctions

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...