<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IF Statement customized EVAL in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/IF-Statement-customized-EVAL/m-p/537026#M151809</link>
    <description>&lt;P&gt;Does this help?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=opennms "uei.opennms.org/nodes/nodeUp" OR "uei.opennms.org/nodes/nodeDown"
| rex field=eventuei "uei.opennms.org/nodes/node(?&amp;lt;Status&amp;gt;.+)"
| stats max(_time) as Time latest(Status) as Status by nodelabel
| lookup ONMS_nodes.csv nodelabel OUTPUT sitecode
| table  sitecode, nodelabel, Status,Time
| where match(nodelabel,"WANRTC|LANCCO|WLNWLC|APNINT")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jan 2021 10:41:43 GMT</pubDate>
    <dc:creator>renjith_nair</dc:creator>
    <dc:date>2021-01-25T10:41:43Z</dc:date>
    <item>
      <title>IF Statement customized EVAL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IF-Statement-customized-EVAL/m-p/537022#M151808</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;need help in my query, formatting an IF statement.&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;My Code:&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=opennms "uei.opennms.org/nodes/nodeUp" OR "uei.opennms.org/nodes/nodeDown"
| rex field=eventuei "uei.opennms.org/nodes/node(?&amp;lt;Status&amp;gt;.+)"
| stats max(_time) as Time latest(Status) as Status by nodelabel
| lookup ONMS_nodes.csv nodelabel OUTPUT sitecode
| table  sitecode, nodelabel, Status,Time&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;My Output:&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;TABLE border="1" width="99.87096774193549%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="18.838709677419356%"&gt;sitecode&lt;/TD&gt;&lt;TD width="38.32258064516129%"&gt;nodelabel&lt;/TD&gt;&lt;TD width="13.806451612903226%"&gt;Status&lt;/TD&gt;&lt;TD width="28.903225806451616%"&gt;Time&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="18.838709677419356%"&gt;ABM&lt;/TD&gt;&lt;TD width="38.32258064516129%"&gt;ARABMLANCCO1&lt;/TD&gt;&lt;TD width="13.806451612903226%"&gt;Up&lt;/TD&gt;&lt;TD width="28.903225806451616%"&gt;1/23/2021 14:35&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="18.838709677419356%"&gt;ABM&lt;/TD&gt;&lt;TD width="38.32258064516129%"&gt;ARABMLANCUA1&lt;/TD&gt;&lt;TD width="13.806451612903226%"&gt;Up&lt;/TD&gt;&lt;TD width="28.903225806451616%"&gt;1/23/2021 8:26&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="18.838709677419356%"&gt;ABM&lt;/TD&gt;&lt;TD width="38.32258064516129%"&gt;ARABMLANCUA2&lt;/TD&gt;&lt;TD width="13.806451612903226%"&gt;Up&lt;/TD&gt;&lt;TD width="28.903225806451616%"&gt;1/23/2021 8:25&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="18.838709677419356%"&gt;ABM&lt;/TD&gt;&lt;TD width="38.32258064516129%"&gt;ARABMWANRTC1&lt;/TD&gt;&lt;TD width="13.806451612903226%"&gt;Up&lt;/TD&gt;&lt;TD width="28.903225806451616%"&gt;1/23/2021 8:25&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="18.838709677419356%"&gt;ABM&lt;/TD&gt;&lt;TD width="38.32258064516129%"&gt;ARABMLANCUA3&lt;/TD&gt;&lt;TD width="13.806451612903226%"&gt;Up&lt;/TD&gt;&lt;TD width="28.903225806451616%"&gt;1/23/2021 8:25&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="18.838709677419356%"&gt;ABM&lt;/TD&gt;&lt;TD width="38.32258064516129%"&gt;ARABMLANCUA4&lt;/TD&gt;&lt;TD width="13.806451612903226%"&gt;Up&lt;/TD&gt;&lt;TD width="28.903225806451616%"&gt;1/23/2021 8:25&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="18.838709677419356%"&gt;ABM&lt;/TD&gt;&lt;TD width="38.32258064516129%"&gt;ARABMAPNOPT1&lt;/TD&gt;&lt;TD width="13.806451612903226%"&gt;Up&lt;/TD&gt;&lt;TD width="28.903225806451616%"&gt;1/19/2021 13:37&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="18.838709677419356%"&gt;ZBQ&lt;/TD&gt;&lt;TD width="38.32258064516129%"&gt;BRZBQLANCUA1&lt;/TD&gt;&lt;TD width="13.806451612903226%"&gt;Up&lt;/TD&gt;&lt;TD width="28.903225806451616%"&gt;1/19/2021 13:37&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Above table am getting from my code.&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Requirement :&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;I want to list down all devices from that sitecode which have any of these name&amp;nbsp;("*WANRTC*" OR "*LANCCO*" OR "*WLNWLC*"OR "*APNINT*") these keyword in nodelabel. rest all site code should be removed from the list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my output. Am having ABM site which matches any of that Keyword and that to be displayed, where as ZBQ doesnt have any of that keyword devices in the list, so it should be removed.&lt;/P&gt;&lt;P&gt;like and IF ("*WANRTC*" OR "*LANCCO*" OR "*WLNWLC*"OR "*APNINT*")&amp;nbsp; any of this present in device names, then the complete list to be displayed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 10:30:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IF-Statement-customized-EVAL/m-p/537022#M151808</guid>
      <dc:creator>jerinvarghese</dc:creator>
      <dc:date>2021-01-25T10:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: IF Statement customized EVAL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IF-Statement-customized-EVAL/m-p/537026#M151809</link>
      <description>&lt;P&gt;Does this help?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=opennms "uei.opennms.org/nodes/nodeUp" OR "uei.opennms.org/nodes/nodeDown"
| rex field=eventuei "uei.opennms.org/nodes/node(?&amp;lt;Status&amp;gt;.+)"
| stats max(_time) as Time latest(Status) as Status by nodelabel
| lookup ONMS_nodes.csv nodelabel OUTPUT sitecode
| table  sitecode, nodelabel, Status,Time
| where match(nodelabel,"WANRTC|LANCCO|WLNWLC|APNINT")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 10:41:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IF-Statement-customized-EVAL/m-p/537026#M151809</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2021-01-25T10:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: IF Statement customized EVAL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IF-Statement-customized-EVAL/m-p/537030#M151810</link>
      <description>&lt;P&gt;This is filtering only devices which have&amp;nbsp;"WANRTC|LANCCO|WLNWLC|APNINT". rest all devices from that site removed. I want other devices also from that site including the above one.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 11:03:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IF-Statement-customized-EVAL/m-p/537030#M151810</guid>
      <dc:creator>jerinvarghese</dc:creator>
      <dc:date>2021-01-25T11:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: IF Statement customized EVAL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/IF-Statement-customized-EVAL/m-p/537046#M151811</link>
      <description>&lt;P&gt;alright,&lt;/P&gt;&lt;P&gt;Try&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=opennms "uei.opennms.org/nodes/nodeUp" OR "uei.opennms.org/nodes/nodeDown"
| rex field=eventuei "uei.opennms.org/nodes/node(?&amp;lt;Status&amp;gt;.+)"
| stats max(_time) as Time latest(Status) as Status by nodelabel
| lookup ONMS_nodes.csv nodelabel OUTPUT sitecode
| table  sitecode, nodelabel, Status,Time
| eventstats values(eval(if(match(nodelabel,"WANRTC|LANCCO|WLNWLC|APNINT"),1,null()))) as isPresent by app
| where isPresent == 1&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 12:37:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/IF-Statement-customized-EVAL/m-p/537046#M151811</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2021-01-25T12:37:27Z</dc:date>
    </item>
  </channel>
</rss>

