Hi there,
I have a table with some columns. Splunk should show a new column with a dynamic value.
When the value of source is Aruba than Splunk should fill the value in the new columns with ABC.
When the value of source is dell than Splunk should fill the value in the new columns with DEF.
and so on...
source="Aruba" OR source="dell" | table source
(simplified search)
Is it possible in Splunk?
Thanks in advance.
Splunk Version 6.3
I guess you're looking for an "EVAL - IF" OR "EVAL -CASE" statement
source="Aruba" OR source="dell" | table source | eval newfield=if(source="Aruba","ABC","DEF")
source="Aruba" OR source="dell" | table source | eval newfield=case(source="Aruba","ABC", source="dell" ,"DEF", 1=1, "Unknown" )