Security

How to update multiple value in same field using eval command?

Rajiv_splunk
Path Finder

HI Everyone,

I am trying to update multiple value in the same field using eval case command but it returning the below error

Error in 'eval' command: The expression is malformed. Expected ).

My requirement is to update when website is ABC the delievery_status should be on_the_way, and when website is xyz the delievery_status should be delievered else it should say Nt delievered. and i am writing the below case statement

| eval delievery_status = case (website="ABC" "on_the_way" website="xyz", "delievered", "Not_delievered")

Can anyone please help me on this what i am missing in this

Labels (1)
Tags (1)
0 Karma
1 Solution

DanielPriceUK
Path Finder

| eval delievery_status =
case (website="ABC","on_the_way",
website="xyz", "delievered",
True(),"Not_delievered")

View solution in original post

Rajiv_splunk
Path Finder

Thanks a lot @DanielPriceUK . It works :)... Thanks for a quick reply

DanielPriceUK
Path Finder

| eval delievery_status =
case (website="ABC","on_the_way",
website="xyz", "delievered",
True(),"Not_delievered")

Rajiv_splunk
Path Finder

Thanks a lot @DanielPriceUK . It works :)... Thanks for a quick reply

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...