Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to create a new field out of values of a current field?

$
0
0
I have a field with event IDs. Some of the IDs indicate an issue, while some of them indicate the opposite. eventid=1 MalwareScanDown eventid=2 MalwareScanUp Eventid=3 SystemOffline EventID=4 SystemOnline EventID=5 PolicyUpdateFail EventID=6 PolicyUpdateSuccuess I want to create a pie chart that shows systems that have a latest status of good, or bad. Is there a way to group the results of eventID=2,4,6 into a new field called good. Likewise, is there a way to group eventid 1,3,6 into a new field called bad?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>