Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

eval expression to create a field with values more than other field

$
0
0
Hi all. I have a field called `src` with values like: 348 55666 77666 95670 23456 I want to create a new field that only shows the values that are greater than 1000, my search string looks like: ... | where src > 1000 I tried directly with ` ... | eval field= where src > 1000` and doesn't work. Also, tested with `eval field=command(search subsearch)` and also doesn't work. Suggestions?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>