Reporting
Highlighted

How to build a report using if condition

Explorer

Now I have two fields(named field 1 and field 2) for one log file. Field 2 just has two kinds of value "1" and "2". I want to build a chart to show field 1's value when field 2's value equals "1". How can I do that? Thanks for any help!

Tags (1)
0 Karma
Highlighted

Re: How to build a report using if condition

Splunk Employee
Splunk Employee

One way...

... | where field2=1 | table field1
Highlighted

Re: How to build a report using if condition

Splunk Employee
Splunk Employee

Or just: source=mylog field2=1 | ...

Highlighted

Re: How to build a report using if condition

Explorer

eh...quite easy...I'm not familiar with Splunk search language...Thank u

0 Karma