Dashboards & Visualizations

Case and coalesce statement in one

VijaySrrie
Builder

Hi Team,

I have an auto-extracted field - auth.policies{}
I have another field called user 
Whenever auth.policies{} is root, I need that to be a part of user field
May I know how to do it? Is there a possibility to use case and coalesce together?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @VijaySrrie ,

yes, you can do it, but (as also @burwell said) I could be more detailed, if you could share your search.

Ciao.

Giuseppe

burwell
SplunkTrust
SplunkTrust

Hi can you say a little more about what the intended field values are that you are trying to achieve?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...