Splunk Search

Is it possible to write switch case statements in Splunk like other programming languages?

soumidutta
Explorer

Hi ,

Can it be possible to write switch case statements in Splunk like other programming languages?
If so, can you help me out with the syntax?

Tags (1)
0 Karma

renjith_nair
Legend

@soumidutta,

Yes , using eval - eval description=case(status == 200, "OK", status ==404, "Not found", status == 500, "Internal Server Error")

http://docs.splunk.com/Documentation/Splunk/7.2.0/SearchReference/ConditionalFunctions#case.28X.2C.2...

Happy Splunking!

soumidutta
Explorer

Thanks
I was looking for this one

0 Karma

renjith_nair
Legend

@soumidutta,
Please accept as answer if it helped you. thanks

Happy Splunking!
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...