<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with Eval command!! in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537106#M467</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/63444"&gt;@chinmay25&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Please try below;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=xyz (source=smf015 OR source=smf014)
| stats values(source) as source by JFCBDSNM DATETIME SMF14JBN SMF14RST SMF14SPN JFCBELNM TIOEDDNM SMF14PGN
| eval Type= case(source=smf014,"Input",source=smf015,"Output",1=1,"Both")
| table DATETIME JFCBDSNM SMF14JBN SMF14SPN TIOEDDNM SMF14PGN Type&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jan 2021 19:48:03 GMT</pubDate>
    <dc:creator>scelikok</dc:creator>
    <dc:date>2021-01-25T19:48:03Z</dc:date>
    <item>
      <title>Help with Eval command!!</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537081#M465</link>
      <description>&lt;P&gt;I am using the following eval command. I want the type column to pick up both the sources.&lt;/P&gt;&lt;P&gt;index=xyz (source=smf015 OR source=smf014)&lt;BR /&gt;| stats values(source) as source by JFCBDSNM DATETIME SMF14JBN SMF14RST SMF14SPN JFCBELNM TIOEDDNM SMF14PGN&lt;BR /&gt;| eval Type= case(source=smf014,Input,source=smf015,Output, (source=smf015 and source=smf014),Both)&lt;BR /&gt;| table DATETIME JFCBDSNM SMF14JBN SMF14SPN TIOEDDNM SMF14PGN Type&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would appreciate the help.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 19:08:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537081#M465</guid>
      <dc:creator>chinmay25</dc:creator>
      <dc:date>2021-01-25T19:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Eval command!!</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537106#M467</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/63444"&gt;@chinmay25&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Please try below;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=xyz (source=smf015 OR source=smf014)
| stats values(source) as source by JFCBDSNM DATETIME SMF14JBN SMF14RST SMF14SPN JFCBELNM TIOEDDNM SMF14PGN
| eval Type= case(source=smf014,"Input",source=smf015,"Output",1=1,"Both")
| table DATETIME JFCBDSNM SMF14JBN SMF14SPN TIOEDDNM SMF14PGN Type&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 19:48:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537106#M467</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-25T19:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Eval command!!</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537112#M468</link>
      <description>&lt;P&gt;Hi Scelikok,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the help. It does work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I may have defined the problem incorrectly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I expect the Type column to pick up is INPUT in place of SMF014 and OUTPUT in place of SMF015.&lt;/P&gt;&lt;P&gt;Looking forward to your suggesstion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chinmay.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 20:05:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537112#M468</guid>
      <dc:creator>chinmay25</dc:creator>
      <dc:date>2021-01-25T20:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Eval command!!</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537122#M469</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/63444"&gt;@chinmay25&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I believed that you want to see "Input" , "Output" or "Both" as text in Type field. The search result must have showing these values. Do you mean Input, Output and Both as another field name? Do you want to see the values of these fields on Type field?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 20:47:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537122#M469</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-25T20:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Eval command!!</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537125#M470</link>
      <description>&lt;P&gt;Hi Scelikok,&lt;/P&gt;&lt;P&gt;I want the result table to have the following column for type. It should not have "Both" in it. In place of SMF014 I want Input and In place of SMF015 I want Output in the Type Column.&lt;/P&gt;&lt;TABLE width="53"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="53"&gt;Type&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Input&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Input&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Input&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Input&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Output&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Input&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Output&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Input&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 25 Jan 2021 21:03:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537125#M470</guid>
      <dc:creator>chinmay25</dc:creator>
      <dc:date>2021-01-25T21:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Eval command!!</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537126#M471</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/63444"&gt;@chinmay25&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I got the problem now, it was not supposed to show all as "Both". Please try below;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=xyz (source=smf015 OR source=smf014)
| stats values(source) as source by JFCBDSNM DATETIME SMF14JBN SMF14RST SMF14SPN JFCBELNM TIOEDDNM SMF14PGN
| eval Type=case(source="smf014","Input",source="smf015","Output",1=1,"Both")
| table DATETIME JFCBDSNM SMF14JBN SMF14SPN TIOEDDNM SMF14PGN Type&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 21:13:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537126#M471</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-25T21:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Eval command!!</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537128#M472</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I tried your latest command with 1=1, "Both". The table still shows Both and not Input or Output.&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;Type&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="100%"&gt;Both&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="100%"&gt;Both&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="100%"&gt;Both&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 25 Jan 2021 21:18:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537128#M472</guid>
      <dc:creator>chinmay25</dc:creator>
      <dc:date>2021-01-25T21:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Eval command!!</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537129#M473</link>
      <description>&lt;P&gt;And If i try the if command, i get a blank column.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 21:18:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537129#M473</guid>
      <dc:creator>chinmay25</dc:creator>
      <dc:date>2021-01-25T21:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Eval command!!</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537132#M474</link>
      <description>&lt;P&gt;Is it possible to be all events are coming from both sources? Can you please show the stats command output before eval?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 21:54:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537132#M474</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-25T21:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Eval command!!</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537134#M475</link>
      <description>&lt;P&gt;This is the result just after the stats command.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinmay25_0-1611612377322.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12661iBF642E68F3D0D168/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinmay25_0-1611612377322.png" alt="chinmay25_0-1611612377322.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 22:06:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537134#M475</guid>
      <dc:creator>chinmay25</dc:creator>
      <dc:date>2021-01-25T22:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Eval command!!</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537144#M476</link>
      <description>&lt;P&gt;Ok, source is not exact match to smf014 or smf015. Please try below;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=xyz (source=smf015 OR source=smf014)
| stats values(source) as source by JFCBDSNM DATETIME SMF14JBN SMF14RST SMF14SPN JFCBELNM TIOEDDNM SMF14PGN
| eval Type=case(mvcount(source)&amp;gt;1,"Both",source LIKE "%smf014","Input",source LIKE "%smf015","Output")
| table DATETIME JFCBDSNM SMF14JBN SMF14SPN TIOEDDNM SMF14PGN Type&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 23:11:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537144#M476</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-25T23:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Eval command!!</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537237#M477</link>
      <description>&lt;P&gt;Hi Scelikok,&lt;/P&gt;&lt;P&gt;Unfortunately, its still not picking up anything in the Type column.&lt;/P&gt;&lt;P&gt;The Type column is blank.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chinmay.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 16:03:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537237#M477</guid>
      <dc:creator>chinmay25</dc:creator>
      <dc:date>2021-01-26T16:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Eval command!!</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537245#M478</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/63444"&gt;@chinmay25&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Please try below, I think it is case sensitivity;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=xyz (source=smf015 OR source=smf014)
| stats values(source) as source by JFCBDSNM DATETIME SMF14JBN SMF14RST SMF14SPN JFCBELNM TIOEDDNM SMF14PGN
| eval Type=case(mvcount(source)&amp;gt;1,"Both",source LIKE "%SMF014","Input",source LIKE "%SMF015","Output")
| table DATETIME JFCBDSNM SMF14JBN SMF14SPN TIOEDDNM SMF14PGN Type&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 26 Jan 2021 16:37:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537245#M478</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-26T16:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Eval command!!</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537260#M479</link>
      <description>&lt;P&gt;Thank you. This solution works.&lt;/P&gt;&lt;P&gt;I had used the append command to make it work, but this is more efficient.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Chinmay.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 17:33:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Help-with-Eval-command/m-p/537260#M479</guid>
      <dc:creator>chinmay25</dc:creator>
      <dc:date>2021-01-26T17:33:11Z</dc:date>
    </item>
  </channel>
</rss>

