Hello Splunk Ninjas,
First time I've seen this: I have two fields, clearly regognised as numeric fields by Splunk. They are named:
"Put Count"
"Put1 Count"
I want to sum these fields, so I do this:
eval Put_Count_Sum= "Put Count" + "Put1 Count"
But instead of Put_Count_Sum
being the sum of both fields, Put_Count_Sum is equal to the text string: "Put CountPut1 Count"
I understand it might have something to do with my fields having spaces, but not sure how to work around that.
Thank you.
Hi @patouellet,
try using
eval Put_Count_Sum= 'Put Count' + 'Put1 Count'
Hi @patouellet,
try using
eval Put_Count_Sum= 'Put Count' + 'Put1 Count'
Thank you works perfectly.