Splunk Search

2 different lookups in if statement.

sumarri
Path Finder

When I search I want something like this:

if(ID =99): then lookup 1,

else: lookup 2.

What I have right now is something like this, but I done know how to put it in the correct syntax: 

| eval To_AccountID= if(ID="99",
[search | lookup Payroll1.csv PARENTACCOUNT OUTPUT Product_Type as To_AccountID, AccountType as To_Account],
[search | lookup Payroll2.csv PARENTACCOUNT, ID as PARENTID OUTPUT TYPE as To_AccountID, AccountType as To_Account])

What is the best way to code something like this??? 

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

SPL is not a procedural language and does not have if...then...else... constructs

Try something like this

| lookup Payroll1.csv PARENTACCOUNT OUTPUT Product_Type as To_AccountID_99, AccountType as To_Account_99
| lookup Payroll2.csv PARENTACCOUNT, ID as PARENTID OUTPUT TYPE as To_AccountID_NOT_99, AccountType as To_Account_NOT_99
| eval To_AccountID= if(ID="99",To_AccountID_99,To_AccountID_NOT_99)

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

SPL is not a procedural language and does not have if...then...else... constructs

Try something like this

| lookup Payroll1.csv PARENTACCOUNT OUTPUT Product_Type as To_AccountID_99, AccountType as To_Account_99
| lookup Payroll2.csv PARENTACCOUNT, ID as PARENTID OUTPUT TYPE as To_AccountID_NOT_99, AccountType as To_Account_NOT_99
| eval To_AccountID= if(ID="99",To_AccountID_99,To_AccountID_NOT_99)

sumarri
Path Finder

That is what I ended up doing, but I want to know if there was another way like that! Looks like it is the only way...

 

Thank you! 

0 Karma
Get Updates on the Splunk Community!

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...