Hi
I am trying to adjust an existing process which collects results of a query into a summary index. What I'm trying to do is add a new evaluated field and pass it into the summary index. I've been looking at the 'marker' option to 'collect', but that passes a string directly rather than the value of the field. Is there any way to pass the value of the field?
This is roughly what I'm trying:
index=<index> <query>
| eval score1 = if(<subquery1>, 1, 0)
| eval score2 = if(<subquery2>, 1, 0)
| eval score_total = score1 + score2
| collect index=<summary_index> marker="score_total=score_total"
I was naively hoping that the 'score_total' field in the summary index (which now exists) would hold the evaluated numeric value, but unfortunately (for me) it contains the string 'score_total'.
Is there any way to achieve what I'm trying to do here? Or some alternative?
Thanks in advance.
Richard
... View more