Hi, everyone
When I create a field concatenated with eval, example: |eval date = day. "/" .month." /". year. |
Can I display the variable date in a table?.
Note: I use Splunk 6.1.
Thanks
Hi cgaete,
if the fields
- day
- month
- year
are valid fields in your data you can do something like this.
| eval date = day + "/" + month + "/" + year | table date
I don't understand; your question is so elemental that it should have taken you 10 times longer to post this question than it could have taken you to actually try it and see that it works. If you really do have a problem, then post samples events and your search.
Hi cgaete,
if the fields
- day
- month
- year
are valid fields in your data you can do something like this.
| eval date = day + "/" + month + "/" + year | table date
I would never use +
for concatenation operator because it also the addition
operator and the latter has higher precedence making an invisible land mine for somebody (maybe even yourself) later on. I think that the original problem was a lack of spaces around each .
operator.