Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

help on where command

$
0
0
hello I use the seatrch below index="*" sourcetype="*" | eval Boot_Duration=coalesce('Durée du démarrage ','Boot Duration ','Startdauer ','Duración del arranque ') | dedup host | stats count by host Boot_Duration is a number value I want to chech only the number values >100000 So I do | where Boot_Duration>100000 But it doesnt works Could you help me please??

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>