Result Modification (SRM) – Zarys informacji

Szczegółowy program szkolenia

Module1 - Manipulating Output

  • Convert a 2-D table into a flat table with the untable command
  • Convert a flat table into a 2-D table with the xyseries command

Module 2 - Modifying Result Sets

  • Append data to search results with the appendpipe command
  • Calculate event statistics with the eventstats command
  • Calculate "streaming" statistics with the streamstats command

Module 3 – Modifying Field Values

  • Understand the eval command
  • Use conversion and text eval functions to modify field values
  • Reformat fields with the foreach command

Module 4 – Normalizing with eval

  • Normalize data with eval functions
  • Identify eval functions to use for data and field normalization