Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

normalizing events with multiple keys

$
0
0
I have a couple of fields, Node and NodeID, which will both have a number, Then I have NodeName which is of the format "Node001" so to make sure they all have a NodeName I did this eval NodeName="Node".substr("000".NodeId,-3) | eval NodeName = "Node".substr("000".Node,-3) However this seems rather wasteful, how would I combine this in to one statement? Its unlikely an event will have both Node and NodeID but I'd have to dig through the data more

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>