<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error in Eval Command in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Error-in-Eval-Command/m-p/63066#M15570</link>
    <description>&lt;P&gt;I am trying to combine 3 separate searches into one.&lt;/P&gt;

&lt;P&gt;The first search begins within sourcetype=pan:traffic. I use the src_translated_port and src_translated_ip to return the src_ip that I am looking for.&lt;/P&gt;

&lt;P&gt;I then want to match that src_ip to the dest_ip within sourcetype=msdhcp, which is currently my second search. I use this search to return the dest_mac that I am looking for.&lt;/P&gt;

&lt;P&gt;The third search is within sourcetype=campusmgr. I want to match the dest_mac returned from sourcetype=msdhcp to the src_mac with sourcetype=campusmgr.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 13:31:32 GMT</pubDate>
    <dc:creator>KNichol5hd</dc:creator>
    <dc:date>2020-09-28T13:31:32Z</dc:date>
    <item>
      <title>Error in Eval Command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-Eval-Command/m-p/63062#M15566</link>
      <description>&lt;P&gt;sourcetype=campusmgr earliest=-72h latest=+72h [search sourcetype=msdhcp earliest=03/10/2013:12:40:00 latest=03/10/2013:15:40:00 | eval dest_ip=if (match(sourcetype,"pan:traffic"),src_ip,"") [search sourcetype=pan:traffic src_translated_port=##### src_translated_ip=###.###.##.## earliest=03/10/2013:12:40:00 latest=03/10/2013:15:40:00 | return 10 src_ip] | return 10 dest_ip] | chart count by user | sort - count&lt;/P&gt;

&lt;P&gt;Error in 'eval' command: The operator at '(src_ip="###.###.##.##") OR (src_ip="###.###.##.##") OR (src_ip="###.###.##.##") OR (src_ip="###.###.##.##")' is invalid.&lt;/P&gt;

&lt;P&gt;Can anyone tell me what I'm doing wrong here?&lt;/P&gt;

&lt;P&gt;*The sourcetype=src_ip in pan:traffic appears as dest_ip in sourcetype=msdhcp.&lt;BR /&gt;
*The dest_mac in sourcetype=msdhcp appears as src_mac in sourcetype=campusmgr.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:31:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-Eval-Command/m-p/63062#M15566</guid>
      <dc:creator>KNichol5hd</dc:creator>
      <dc:date>2020-09-28T13:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Eval Command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-Eval-Command/m-p/63063#M15567</link>
      <description>&lt;P&gt;Well you're tacking on a subsearch directly onto an &lt;CODE&gt;eval&lt;/CODE&gt; statement. That's why you're getting an error.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2013 14:20:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-Eval-Command/m-p/63063#M15567</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-03-15T14:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Eval Command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-Eval-Command/m-p/63064#M15568</link>
      <description>&lt;P&gt;This the first I've ever worked with subsearches. Do you know what the correct format should be?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2013 14:22:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-Eval-Command/m-p/63064#M15568</guid>
      <dc:creator>KNichol5hd</dc:creator>
      <dc:date>2013-03-15T14:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Eval Command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-Eval-Command/m-p/63065#M15569</link>
      <description>&lt;P&gt;Depends. What's the purpose of the subsearch?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2013 14:24:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-Eval-Command/m-p/63065#M15569</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-03-15T14:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Eval Command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-Eval-Command/m-p/63066#M15570</link>
      <description>&lt;P&gt;I am trying to combine 3 separate searches into one.&lt;/P&gt;

&lt;P&gt;The first search begins within sourcetype=pan:traffic. I use the src_translated_port and src_translated_ip to return the src_ip that I am looking for.&lt;/P&gt;

&lt;P&gt;I then want to match that src_ip to the dest_ip within sourcetype=msdhcp, which is currently my second search. I use this search to return the dest_mac that I am looking for.&lt;/P&gt;

&lt;P&gt;The third search is within sourcetype=campusmgr. I want to match the dest_mac returned from sourcetype=msdhcp to the src_mac with sourcetype=campusmgr.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-Eval-Command/m-p/63066#M15570</guid>
      <dc:creator>KNichol5hd</dc:creator>
      <dc:date>2020-09-28T13:31:32Z</dc:date>
    </item>
  </channel>
</rss>

