<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to build a report using if condition in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/How-to-build-a-report-using-if-condition/m-p/97089#M2232</link>
    <description>&lt;P&gt;Or just: &lt;CODE&gt;source=mylog field2=1 | ...&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Dec 2010 12:56:56 GMT</pubDate>
    <dc:creator>gkanapathy</dc:creator>
    <dc:date>2010-12-01T12:56:56Z</dc:date>
    <item>
      <title>How to build a report using if condition</title>
      <link>https://community.splunk.com/t5/Reporting/How-to-build-a-report-using-if-condition/m-p/97087#M2230</link>
      <description>&lt;P&gt;Now I have two fields(named field 1 and field 2) for one log file. Field 2 just has two kinds of value "1" and "2". I want to build a chart to show field 1's value when field 2's value equals "1". How can I do that? Thanks for any help!&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2010 11:49:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-to-build-a-report-using-if-condition/m-p/97087#M2230</guid>
      <dc:creator>zeaxodarap</dc:creator>
      <dc:date>2010-12-01T11:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to build a report using if condition</title>
      <link>https://community.splunk.com/t5/Reporting/How-to-build-a-report-using-if-condition/m-p/97088#M2231</link>
      <description>&lt;P&gt;One way...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | where field2=1 | table field1
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 01 Dec 2010 12:28:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-to-build-a-report-using-if-condition/m-p/97088#M2231</guid>
      <dc:creator>bwooden</dc:creator>
      <dc:date>2010-12-01T12:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to build a report using if condition</title>
      <link>https://community.splunk.com/t5/Reporting/How-to-build-a-report-using-if-condition/m-p/97089#M2232</link>
      <description>&lt;P&gt;Or just: &lt;CODE&gt;source=mylog field2=1 | ...&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2010 12:56:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-to-build-a-report-using-if-condition/m-p/97089#M2232</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-12-01T12:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to build a report using if condition</title>
      <link>https://community.splunk.com/t5/Reporting/How-to-build-a-report-using-if-condition/m-p/97090#M2233</link>
      <description>&lt;P&gt;eh...quite easy...I'm not familiar with Splunk search language...Thank u&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2010 14:57:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/How-to-build-a-report-using-if-condition/m-p/97090#M2233</guid>
      <dc:creator>zeaxodarap</dc:creator>
      <dc:date>2010-12-01T14:57:27Z</dc:date>
    </item>
  </channel>
</rss>

