Knowledge Management

How to use calculated fields created using Splunk Web in search?

indusbull
Explorer

Hi
I created a calculated field called "SUCCESS" using Splunk Web on sourcetype. The calculated field eval condition is like if(TYPE="S", "Success", null). Now I am trying to use this calculated field in my search like below -

index=customindex sourcetype=customsource | stats count(SUCCESS) as SuccessCount

But this returns no results and I know there are events in source that qualifies eval conditions. Not sure what I am doing wrong?

Before my search used to be like below for ref -

 index=customindex sourcetype=customsource | eval Success=if(TYPE=="S", "Success", null) | stats count(Success) as SuccessCount
0 Karma
1 Solution

niketn
Legend

@indusbull, since your second query is working, seems like issue is with how you have created Calculated field.

First thing you have to remember is that the field name that you use for Calculated Field will be case sensitive. So as per your second example the field name is actually Success and not SUCCESS.

Second, you can use case() instead of if() to set the Success field value to "SUCCESS", if TYPE="S" and do not set the value for any other type i.e. null. So the eval expression would be

|  eval Success=case(TYPE=="S","SUCCESS")

Following is how Calculated Field Configuration should look like. Please compare and validate (props.conf😞

[customsource]
EVAL-Success = case(TYPE=="S","SUCCESS")
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

niketn
Legend

@indusbull, since your second query is working, seems like issue is with how you have created Calculated field.

First thing you have to remember is that the field name that you use for Calculated Field will be case sensitive. So as per your second example the field name is actually Success and not SUCCESS.

Second, you can use case() instead of if() to set the Success field value to "SUCCESS", if TYPE="S" and do not set the value for any other type i.e. null. So the eval expression would be

|  eval Success=case(TYPE=="S","SUCCESS")

Following is how Calculated Field Configuration should look like. Please compare and validate (props.conf😞

[customsource]
EVAL-Success = case(TYPE=="S","SUCCESS")
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

indusbull
Explorer

Thanks. The real issue was with if(). Using cas() solved it.

niketn
Legend

@indusbull, glad it worked. I am surprised though, as to how your second search worked with if()

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...