Splunk Search

Add 2 columns in a table on applied condition

nivethainspire_
Explorer

I have 3 columns in a table as below.
I need to sum two colums(mag and depth) if place="7km W of Cobb,california" or "1km se of loma linda,california".
show the result in mag and make depth as 0 column as 0 on applied condition(place).alt text

my result should be as follows:
alt text
Please help me to make a query for my condition.

0 Karma
1 Solution

gokadroid
Motivator
your Base query to generate place , mag, depth
| eval mag=if(place="7km W of Cobb, California" OR place="1km SE of Loma Linda, California", mag+depth, mag)
| eval depth=if(place="7km W of Cobb, California" OR place="1km SE of Loma Linda, California", 0, depth)
| table place, mag, depth

View solution in original post

0 Karma

gokadroid
Motivator
your Base query to generate place , mag, depth
| eval mag=if(place="7km W of Cobb, California" OR place="1km SE of Loma Linda, California", mag+depth, mag)
| eval depth=if(place="7km W of Cobb, California" OR place="1km SE of Loma Linda, California", 0, depth)
| table place, mag, depth
0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...