|
Trying to emulate example given here, but totals always come up zero. Basic search returns over 1,000 events for a 4 hour period, containing 4 eventcodes: 636, 637, 4732, 4733.
Splunk GUI returns: Specified field(s) missing from results: 'Eval(EventCode=636)', 'Eval(EventCode=637)' Have also tried if, case, and like functions of eval (with & without quoted aurguments):
Answer here looks promising, but can't get bin and stats to work either. Final goal, after I get the basic chart to work, is to change to timechart:
|
|
Thanks - one day maybe I'll get used to the case sensitivity almost everywhere!
(08 Dec '10, 16:16)
rgcox1
|
