Hello
I am trying to enable the drilldown option and when the drilldown is taking place the search is not able to go back to the original data. It's because of this
rename 1 as Emergency 2 as High, 3 as Medium, 4 as Low
The data is in 1,2,3,4 priorities and I had to rename it so that it comes in the format needed. But when drilldown is being done its searching for "high" and the data is not available.
Any idea on how do I solve this issue?
Yes, fieldformat
is the correct solution. Instead of rename
, do this:
... | fieldformat 1 = Emergency
| fieldformat 2 = High
| fieldformat 3 = Medium
| fieldformat 4 = Low
There two ways to fix it.
1. Pass the token values to the drill-downs with original names
2. Just follow the same naming in the drill-downs as well, what I mean is just rename the fields as in your main search.
Hope this helps, Thanks!
you can do like this
-Kamal Bisht
I believe fieldformat
(http://docs.splunk.com/Documentation/Splunk/5.0/SearchReference/Fieldformat ) is precisely what you're looking for.
Oh.Ok. Will see if there is any other way. Thanks for all the help.
I suspect that might be because your dots in the fieldnames. That is likely to cause troubles one way or another because dots are also interpreted as concatenation operators when using eval
.
It gives an error saying operator == has been given different values.
Well record.priority is a field in the data. So thats the only field which I will be using.. Will it be like this below
fieldformat record.priority=case(record.priority==1,"Emergency",record.priority==2,"High",record.priority==3,"Medium",record.priority==4,"Low")
You're switching priority and record.priority a bit. Are you using both?
....|dedup record.nextBreachTime| rex field=record.nextBreachTime "\s+(?
It still doesn't work. Here is the complete search string. Also if you can, please let me know if I can actually place alphabets in the "Timeperiod" case statements rather than bucketing it according to numbers. I wanted to use 'Count at 0' for '1' in the case statements. Any idea
Sure. With a fieldname called "priority", at the end of your search, add something like this:
... | fieldformat priority=case(priority==1,"Emergency",priority==2,"High",priority==3,"Medium",priority==4,"Low")
Hmm.. I did try the fieldformat but it isn't working. May be I am using it in a wrong way.
Can you please give an example considering the above case on how do we use it?
The field which gives the data about the priority is record.priority.