<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Eval Case Statement not working in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Eval-Case-Statement-not-working/m-p/341350#M101199</link>
    <description>&lt;P&gt;Not sure why the below is not working.  &lt;/P&gt;

&lt;P&gt;index=www_kinesis rtData.tag=pageviewTag  |  eval marketing_channel=case(rtData.referralUrl=="&lt;A href="https://www.google.com/" target="_blank"&gt;https://www.google.com/&lt;/A&gt;", "Natural Search", 1=1, "Direct Load") | table sessionId, marketing_channel, rtData.referralUrl&lt;/P&gt;

&lt;P&gt;All I basically want is, if my rtData.referralUrl= &lt;A href="https://www.google.com/" target="_blank"&gt;https://www.google.com/&lt;/A&gt; to output "Natural Search".  For some reason I've done equals and I've tried even case match, and I'm still not returning "Natural Search", even though my referralUrl is clearly &lt;A href="https://www.google.com/" target="_blank"&gt;https://www.google.com/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 16:32:35 GMT</pubDate>
    <dc:creator>lorellpascual</dc:creator>
    <dc:date>2020-09-29T16:32:35Z</dc:date>
    <item>
      <title>Eval Case Statement not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Eval-Case-Statement-not-working/m-p/341350#M101199</link>
      <description>&lt;P&gt;Not sure why the below is not working.  &lt;/P&gt;

&lt;P&gt;index=www_kinesis rtData.tag=pageviewTag  |  eval marketing_channel=case(rtData.referralUrl=="&lt;A href="https://www.google.com/" target="_blank"&gt;https://www.google.com/&lt;/A&gt;", "Natural Search", 1=1, "Direct Load") | table sessionId, marketing_channel, rtData.referralUrl&lt;/P&gt;

&lt;P&gt;All I basically want is, if my rtData.referralUrl= &lt;A href="https://www.google.com/" target="_blank"&gt;https://www.google.com/&lt;/A&gt; to output "Natural Search".  For some reason I've done equals and I've tried even case match, and I'm still not returning "Natural Search", even though my referralUrl is clearly &lt;A href="https://www.google.com/" target="_blank"&gt;https://www.google.com/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:32:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Eval-Case-Statement-not-working/m-p/341350#M101199</guid>
      <dc:creator>lorellpascual</dc:creator>
      <dc:date>2020-09-29T16:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Eval Case Statement not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Eval-Case-Statement-not-working/m-p/341351#M101200</link>
      <description>&lt;P&gt;The field name you used in eval contains special characters (dot) so they need to be enclosed within single quotes (this is applicable for eval and where commands). Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=www_kinesis rtData.tag=pageviewTag | eval marketing_channel=case('rtData.referralUrl'=="https://www.google.com/", "Natural Search", 1=1, "Direct Load") | table sessionId, marketing_channel, rtData.referralUrl
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 01 Nov 2017 17:30:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Eval-Case-Statement-not-working/m-p/341351#M101200</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-11-01T17:30:43Z</dc:date>
    </item>
  </channel>
</rss>

