I would like realize a sum of data like that par exemple :
data = data + val1
But splunk dioesn’t recognize this sum.
Do you know I can do that ?
can you provide entire query in 101010
sample code format?also can you provide some sample input and output you want ??
Hi @isachristophe,
try to convert string into number by convert
command
<base search>| convert num(data) as data |eval data = data + val1
No it doesn’t work .
Even if you put this instruction :
Convert num (compteur) as compteur | eval compteur = compteur + 1 | table compteur
You have nothing in compteur
what value is present in compteur?
and have you tried same code...as I can see space in between num and (.
provide entire query in 101010 sample code format.
I would like to put in compteur the precedent value of the iteration, but it seems impossible
provide sample input and output you expect
| makeresults | eval data="111222"
| eval val1=666
| convert num(data) | eval data = data + val1
| table data
Its working fine...given result as "111888"
If you can try please -
index="<any_index>"
| eval data="111222"
| eval val1=666
| convert num(data) as data
| eval data = data + val1
| table data