Hi,
I've done a search that uses eval with two searches to get the final result. Then, I'm trying to see the result as a Single Value, however, as the Single Value uses the first column and my the final result is set on the third one, I can't.
See my search below and the table that results from it.
index= "index_cbo_pt" "AcquirerResponseCode=0" | stats count as Result1 | appendcols [search index= "index_cbo_pt" "AcquirerResponseCode=0" | stats dc(MerchantCheckoutId) as Result2] | eval finalValue = Result1/Result2
If you need all three values, try re-ordering them by adding | table finalValue Result1 Result2
to your query.
If you only need finalValue, try appending | fields finalValue
or | table finalValue
to your query.
If you need all three values, try re-ordering them by adding | table finalValue Result1 Result2
to your query.
If you only need finalValue, try appending | fields finalValue
or | table finalValue
to your query.
Thank you very much!
I was thinking about using the result with timechart, could you help me?
Possibly, but for the benefit of future readers, you should submit a new question.
Done. I've submitted here: https://answers.splunk.com/answers/332863/how-do-i-represent-an-eval-result-with-timechart.html?minQ...
Ok. I was doing it, however, as I just have 22 points I need to wait until tomorrow. It just doesn't make sense...