<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CASE command in Props.conf in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/CASE-command-in-Props-conf/m-p/545404#M154475</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/196109"&gt;@pavanbmishra&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you verify the local.meta of your apps folder? And also the after placing the props.conf in search head can you quickly restart and check if it is a single instance. For distributed search head cluster no restart required.&lt;/P&gt;&lt;P&gt;The only eval is not working all other fields are working fine?&lt;/P&gt;</description>
    <pubDate>Thu, 25 Mar 2021 14:05:47 GMT</pubDate>
    <dc:creator>Vardhan</dc:creator>
    <dc:date>2021-03-25T14:05:47Z</dc:date>
    <item>
      <title>CASE command in Props.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/CASE-command-in-Props-conf/m-p/545390#M154469</link>
      <description>&lt;P&gt;Hello SMEs....Seeking helping hand&lt;/P&gt;&lt;P&gt;I got stuck while putting EVAL-&amp;lt;field-name&amp;gt; in props.conf using case command and it is not at all working while the same is working in search bar in GUI. As suggestion would be highly appreciated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EVAL-XYZ = case(src== "AAA", field1, src== "BBB", field2 , src== "CCC", field3)&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 13:31:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/CASE-command-in-Props-conf/m-p/545390#M154469</guid>
      <dc:creator>pavanbmishra</dc:creator>
      <dc:date>2021-03-25T13:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: CASE command in Props.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/CASE-command-in-Props-conf/m-p/545394#M154470</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/196109"&gt;@pavanbmishra&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The eval -xyz filed name have you used anywhere else in the same props. conf? And where exactly have you placed the props. conf?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 13:41:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/CASE-command-in-Props-conf/m-p/545394#M154470</guid>
      <dc:creator>Vardhan</dc:creator>
      <dc:date>2021-03-25T13:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: CASE command in Props.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/CASE-command-in-Props-conf/m-p/545402#M154474</link>
      <description>&lt;P&gt;Thanks Vardhan for your quick help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;No i am not using that eval-xyz field anywhere in the props.conf, i put my config file under below folder&lt;/P&gt;&lt;P&gt;/etc/apps/&amp;lt;app-name&amp;gt;/local folder&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 13:55:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/CASE-command-in-Props-conf/m-p/545402#M154474</guid>
      <dc:creator>pavanbmishra</dc:creator>
      <dc:date>2021-03-25T13:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: CASE command in Props.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/CASE-command-in-Props-conf/m-p/545404#M154475</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/196109"&gt;@pavanbmishra&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you verify the local.meta of your apps folder? And also the after placing the props.conf in search head can you quickly restart and check if it is a single instance. For distributed search head cluster no restart required.&lt;/P&gt;&lt;P&gt;The only eval is not working all other fields are working fine?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 14:05:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/CASE-command-in-Props-conf/m-p/545404#M154475</guid>
      <dc:creator>Vardhan</dc:creator>
      <dc:date>2021-03-25T14:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: CASE command in Props.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/CASE-command-in-Props-conf/m-p/545408#M154478</link>
      <description>&lt;P&gt;Yeah all filed working except that eval expression. What should i check under local.meta ?&lt;/P&gt;&lt;P&gt;BTW it is single instance and i restarted that also. Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 14:15:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/CASE-command-in-Props-conf/m-p/545408#M154478</guid>
      <dc:creator>pavanbmishra</dc:creator>
      <dc:date>2021-03-25T14:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: CASE command in Props.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/CASE-command-in-Props-conf/m-p/545411#M154480</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/196109"&gt;@pavanbmishra&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Can you try with the below eval and see the result.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;EVAL-XYZ = case(src== "AAA", "field1", src== "BBB", "field2" , src== "CCC", "field3")&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And also make sure you are able to see the mentioned src fields values in the case.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 14:23:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/CASE-command-in-Props-conf/m-p/545411#M154480</guid>
      <dc:creator>Vardhan</dc:creator>
      <dc:date>2021-03-25T14:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: CASE command in Props.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/CASE-command-in-Props-conf/m-p/545470#M154508</link>
      <description>&lt;P&gt;I would suggest to add a default option at the end to see whether this eval just doesn't match any of your options (or your sourcetype?) and go from there. Generally, it looks correct. Case-sensitivity for field names is my only idea. Try this and see if you at least get your field with the default value:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;EVAL-XYZ = case(src="AAA", field1, src="BBB", field2 , src="CCC", field3, 1=1, "HITTING DEFAULT IN EVAL")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;If this doesn't help and you can, please post your exact props.conf file&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 19:17:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/CASE-command-in-Props-conf/m-p/545470#M154508</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2021-03-25T19:17:39Z</dc:date>
    </item>
  </channel>
</rss>

