<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: REX pipe to EVAL in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/REX-pipe-to-EVAL/m-p/31209#M6432</link>
    <description>&lt;P&gt;You should be using == instead of =.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;foo=something | REX "start(?&amp;lt;"name"&amp;gt;.*)end" | EVAL NameColor=case(name==1,"red",name==2,"blue") | table _time NameColor
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 13 Feb 2013 19:24:42 GMT</pubDate>
    <dc:creator>emiller42</dc:creator>
    <dc:date>2013-02-13T19:24:42Z</dc:date>
    <item>
      <title>REX pipe to EVAL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REX-pipe-to-EVAL/m-p/31207#M6430</link>
      <description>&lt;P&gt;I have a search that is | to REX then | to EVAL that is not working.  I'm sure it must be a timing issue something like this&lt;/P&gt;

&lt;P&gt;Search &lt;CODE&gt;foo=something | REX "start(?&amp;lt;"name"&amp;gt;.*)end" | EVAL NameColor=case(name=1,"red",name=2,"blue") | table _time NameColor&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;When I do the search without the eval i get results for "name" when I add the EVAL i get no results?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2013 19:03:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REX-pipe-to-EVAL/m-p/31207#M6430</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-02-13T19:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: REX pipe to EVAL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REX-pipe-to-EVAL/m-p/31208#M6431</link>
      <description>&lt;P&gt;You might want to try this: &lt;CODE&gt;foo=something | rex "start(?&amp;lt;name&amp;gt;.*)end" | eval NameColor = case(name=1,"red",name=2,"blue")| table _time NameColor&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;You don't need the quotes in the rex for the field "name". If that doesn't work, kindly post some example data to better help with regex. &lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2013 19:23:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REX-pipe-to-EVAL/m-p/31208#M6431</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-02-13T19:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: REX pipe to EVAL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REX-pipe-to-EVAL/m-p/31209#M6432</link>
      <description>&lt;P&gt;You should be using == instead of =.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;foo=something | REX "start(?&amp;lt;"name"&amp;gt;.*)end" | EVAL NameColor=case(name==1,"red",name==2,"blue") | table _time NameColor
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 13 Feb 2013 19:24:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REX-pipe-to-EVAL/m-p/31209#M6432</guid>
      <dc:creator>emiller42</dc:creator>
      <dc:date>2013-02-13T19:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: REX pipe to EVAL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REX-pipe-to-EVAL/m-p/31210#M6433</link>
      <description>&lt;P&gt;Thanks for the responce I only put the " " in to make name sow in the window.  I don't use the "" in the code like you sugested&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2013 19:26:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REX-pipe-to-EVAL/m-p/31210#M6433</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-02-13T19:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: REX pipe to EVAL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REX-pipe-to-EVAL/m-p/31211#M6434</link>
      <description>&lt;P&gt;In that case, do what emiller42 said. &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2013 19:27:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REX-pipe-to-EVAL/m-p/31211#M6434</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-02-13T19:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: REX pipe to EVAL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REX-pipe-to-EVAL/m-p/31212#M6435</link>
      <description>&lt;P&gt;Thanks emiller I tried that already.  Thanks for contributing.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2013 19:27:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REX-pipe-to-EVAL/m-p/31212#M6435</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-02-13T19:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: REX pipe to EVAL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REX-pipe-to-EVAL/m-p/31213#M6436</link>
      <description>&lt;P&gt;The == is the proper operator for comparison according to the splunk documentation.&lt;/P&gt;

&lt;P&gt;For a working example of what you're trying to do, use the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal sourcetype="splunkd" component="StatusMgr" | rex "source(?&amp;lt;value&amp;gt;.+?)=" | eval test=case(value=="Host", "This is a host", value=="Port", "This is a port") | table value test
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you're not getting results from your rex but not your eval, then the conditions of your case statement don't actually match the values being set in the rex.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2013 19:46:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REX-pipe-to-EVAL/m-p/31213#M6436</guid>
      <dc:creator>emiller42</dc:creator>
      <dc:date>2013-02-13T19:46:18Z</dc:date>
    </item>
  </channel>
</rss>

