I would like to use an if statement to create a new field based on a value. Something like if field1=0 and field2=0, then create new field with value of 1.
Hi, you can use that. Follow an old question about it: https://answers.splunk.com/answers/10947/if-statement-with-multiple-tests.html
View solution in original post
| eval newfield=if(field1=0 and field2=0,1,null)
If you want to use case statement this may helps
search | eval newfield=case(field1=field2,1,1=1,0)