Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Can i use "job.resultCount" in Splunk 6.2.14?

$
0
0
Hi All, I am new to Splunk and am facing an issue with assigning token value based on condition. I'm using the following code:
host="swaroops-MacBook-Pro.local" "Total Records processed" | stats count$earliest$$latest$$redlight_mod1.png$0case($result.count$>=1 ,"$greenlight_mod1.png$")$result.count$
$ST_upstream_value
My version of Splunk is 6.2.14, and yes, I did try after removing the $$ in greenlight_mod1.png as well. But the output I'm getting is `$ST_upstream_value$`, and instead of image, it's showing as a ? mark in the blue box. Looks like the lines after the condition match are not being executed. Can someone please tell me what I'm doing that's causing this error? And, if its a problem of version, do you know how i can achieve this with version 6.2.14. ? I would be really grateful, as I have been stuck for almost 3 weeks at this point. Thanks in advance.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>