I am planning to convert the value of a count into 5k, 500k format rather than the whole number. May I know how I can achieve this? I am trying to use this in Single value panel in a Splunk dashboard. Currently my query looks as follows
.........| timechart span=1mon count
Hi @arrangineni,
Maybe this way can help. Do not know if there is a better way.
| eval count=round((count / 1000),0)
| eval count=count + "k"
Hi @arrangineni,
Maybe this way can help. Do not know if there is a better way.
| eval count=round((count / 1000),0)
| eval count=count + "k"