<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Create static fields after matching the field value in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697748#M237000</link>
    <description>&lt;P&gt;Use the &lt;FONT face="courier new,courier"&gt;eval&lt;/FONT&gt; command to create a field.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval Health = if(status="Issue", "Bad", "Ok")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Aug 2024 18:53:14 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2024-08-29T18:53:14Z</dc:date>
    <item>
      <title>Create static fields after matching the field value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697721#M236993</link>
      <description>&lt;P&gt;I want to create one static field by looking status value = Issue&lt;/P&gt;&lt;TABLE border="0" width="192" cellspacing="0" cellpadding="0"&gt;&lt;COLGROUP&gt;&lt;COL width="64" /&gt;&lt;/COLGROUP&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64" height="19"&gt;host&lt;/TD&gt;&lt;TD width="64"&gt;m_nname&lt;/TD&gt;&lt;TD width="64"&gt;status&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="19"&gt;A&lt;/TD&gt;&lt;TD&gt;cpu&lt;/TD&gt;&lt;TD&gt;Ok&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="19"&gt;B&lt;/TD&gt;&lt;TD&gt;disk&lt;/TD&gt;&lt;TD&gt;Ok&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="19"&gt;C&lt;/TD&gt;&lt;TD&gt;memory&lt;/TD&gt;&lt;TD&gt;Issue&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="19"&gt;D&lt;/TD&gt;&lt;TD&gt;netwok&lt;/TD&gt;&lt;TD&gt;Ok&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="19"&gt;E&lt;/TD&gt;&lt;TD&gt;storage&lt;/TD&gt;&lt;TD&gt;Issue&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issue found in status column few field heath created with Bad value.&lt;/P&gt;&lt;P&gt;Like below.&lt;/P&gt;&lt;TABLE border="0" width="256" cellspacing="0" cellpadding="0"&gt;&lt;COLGROUP&gt;&lt;COL width="64" /&gt;&lt;/COLGROUP&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64" height="19"&gt;host&lt;/TD&gt;&lt;TD width="64"&gt;m_nname&lt;/TD&gt;&lt;TD width="64"&gt;status&lt;/TD&gt;&lt;TD width="64"&gt;Health&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="19"&gt;A&lt;/TD&gt;&lt;TD&gt;cpu&lt;/TD&gt;&lt;TD&gt;Ok&lt;/TD&gt;&lt;TD&gt;Bad&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="19"&gt;B&lt;/TD&gt;&lt;TD&gt;disk&lt;/TD&gt;&lt;TD&gt;Ok&lt;/TD&gt;&lt;TD&gt;Bad&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="19"&gt;C&lt;/TD&gt;&lt;TD&gt;memory&lt;/TD&gt;&lt;TD&gt;Issue&lt;/TD&gt;&lt;TD&gt;Bad&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="19"&gt;D&lt;/TD&gt;&lt;TD&gt;netwok&lt;/TD&gt;&lt;TD&gt;Ok&lt;/TD&gt;&lt;TD&gt;Bad&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="19"&gt;E&lt;/TD&gt;&lt;TD&gt;storage&lt;/TD&gt;&lt;TD&gt;Issue&lt;/TD&gt;&lt;TD&gt;Bad&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 14:52:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697721#M236993</guid>
      <dc:creator>RSS_STT</dc:creator>
      <dc:date>2024-08-29T14:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: Create static fields after matching the field value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697748#M237000</link>
      <description>&lt;P&gt;Use the &lt;FONT face="courier new,courier"&gt;eval&lt;/FONT&gt; command to create a field.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval Health = if(status="Issue", "Bad", "Ok")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 18:53:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697748#M237000</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-08-29T18:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: Create static fields after matching the field value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697749#M237001</link>
      <description>&lt;P&gt;Are you saying that you want a health field that has "Bad" in for all the events if any of the events have status="Issue"?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 18:58:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697749#M237001</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-29T18:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: Create static fields after matching the field value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697759#M237006</link>
      <description>&lt;P&gt;It's not clear how the health field is calculated. One way is what &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt; showed but it won't match your mockup results - you have health=bad all acros the board.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 19:59:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697759#M237006</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-29T19:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: Create static fields after matching the field value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697793#M237014</link>
      <description>&lt;P&gt;Yes, Your understanding is correct.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 06:05:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697793#M237014</guid>
      <dc:creator>RSS_STT</dc:creator>
      <dc:date>2024-08-30T06:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: Create static fields after matching the field value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697801#M237017</link>
      <description>&lt;LI-CODE lang="markup"&gt;| eventstats values(eval(if(status="Issue","Bad",null()))) as Health&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 30 Aug 2024 06:53:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697801#M237017</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-30T06:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Create static fields after matching the field value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697958#M237064</link>
      <description>&lt;P&gt;It's missing the fields value if all Ok.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need Health field to be populated with Ok if all status field have all Ok value.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 09:41:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697958#M237064</guid>
      <dc:creator>RSS_STT</dc:creator>
      <dc:date>2024-09-02T09:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Create static fields after matching the field value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697966#M237070</link>
      <description>&lt;LI-CODE lang="markup"&gt;| eventstats values(eval(if(status="Issue","Bad",null()))) as Health
| fillnull value="Ok" Health&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 02 Sep 2024 10:11:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Create-static-fields-after-matching-the-field-value/m-p/697966#M237070</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-09-02T10:11:55Z</dc:date>
    </item>
  </channel>
</rss>

