<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: eval field is not working in where condition in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743560#M241113</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309102"&gt;@shraddha09&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not really sure I understand what you're looking for, however generally eval should be done BEFORE you run your where statement.&lt;/P&gt;&lt;P&gt;Please could you share the SPL which is not working as expected so we can help further?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding kudos to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
    <pubDate>Fri, 04 Apr 2025 21:35:58 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-04-04T21:35:58Z</dc:date>
    <item>
      <title>eval field is not working in where condition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743552#M241109</link>
      <description />
      <pubDate>Fri, 04 Apr 2025 18:57:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743552#M241109</guid>
      <dc:creator>shraddha09</dc:creator>
      <dc:date>2025-04-04T18:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: eval field is not working in where condition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743554#M241111</link>
      <description>&lt;P&gt;We need more information.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 19:50:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743554#M241111</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-04-04T19:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: eval field is not working in where condition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743560#M241113</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309102"&gt;@shraddha09&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not really sure I understand what you're looking for, however generally eval should be done BEFORE you run your where statement.&lt;/P&gt;&lt;P&gt;Please could you share the SPL which is not working as expected so we can help further?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding kudos to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 21:35:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743560#M241113</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-04T21:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: eval field is not working in where condition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743597#M241120</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309102"&gt;@shraddha09&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as also&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;said, it's really difficoult to help you without any information.&lt;/P&gt;&lt;P&gt;The only additional information that I can add is that you cannot use an eval condition in a where command: you must use the eval command and then in a different row the where condition.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 05 Apr 2025 17:08:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743597#M241120</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-04-05T17:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: eval field is not working in where condition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743665#M241133</link>
      <description>&lt;P&gt;Here is my SPL query,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=wf_eit_ecio) | eval lstUlid=max('Properties.Gems.DataSyncsExecutionContext.dataSyncProvidersExecutionGroupULID') |&amp;nbsp; where 'Properties.Gems.DataSyncsExecutionContext.dataSyncProvidersExecutionGroupULID' = lstUlid | chart count(Properties.Gems.DataSyncExecutionContext.DataSyncProviderName) as TotalApiCallsCount Over Properties.Gems.DataSyncExecutionContext.DataSyncProviderName&lt;/P&gt;&lt;P&gt;lstUlid field is generated but its not working in where condition and not filtering the records&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 09:00:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743665#M241133</guid>
      <dc:creator>shraddha09</dc:creator>
      <dc:date>2025-04-07T09:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: eval field is not working in where condition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743670#M241134</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309102"&gt;@shraddha09&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you cannot use max in the eval command, max can be used only in stats or similar streaming commands.&lt;/P&gt;&lt;P&gt;try something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=wf_eit_ecio) 
| rename
     'Properties.Gems.DataSyncsExecutionContext.dataSyncProvidersExecutionGroupULID' AS GroupULID
     'Properties.Gems.DataSyncExecutionContext.DataSyncProviderName' AS ProviderName
|  where GroupULID = lstUlid 
| stats max(GroupULID) AS max BY ProviderName
| chart count(max) as TotalApiCallsCount BY ProviderName&lt;/LI-CODE&gt;&lt;P&gt;I supposed that&amp;nbsp;lstUlid is a threshold.&lt;/P&gt;&lt;P&gt;another thing, don't bring these so long field names, rename them after the main search.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 10:36:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743670#M241134</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-04-07T10:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: eval field is not working in where condition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743671#M241135</link>
      <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| streamstats max('Properties.Gems.DataSyncsExecutionContext.dataSyncProvidersExecutionGroupULID') as lstUlid
|  where 'Properties.Gems.DataSyncsExecutionContext.dataSyncProvidersExecutionGroupULID' = lstUlid&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 07 Apr 2025 11:11:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743671#M241135</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-04-07T11:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: eval field is not working in where condition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743678#M241136</link>
      <description>&lt;P&gt;rename fields are not showing with | table command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 11:37:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-field-is-not-working-in-where-condition/m-p/743678#M241136</guid>
      <dc:creator>shraddha09</dc:creator>
      <dc:date>2025-04-07T11:37:27Z</dc:date>
    </item>
  </channel>
</rss>

