Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to use timechart with Eval command

$
0
0
index=storage source="/*******.csv" | stats sum(00_*) //It represents sum of various fields | eval sum1=0 | foreach sum* [ eval sum1=sum1+'<>'] | addinfo | eval time_in_min=(info_max_time-info_min_time)/60 | eval sum1=sum1/time_in_min //It shows the average value | fields sum1 I need timechart for sum1 with above data, is it possible ? Any help would be appreciated. Thanks in Advance

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>