Splunk Search

Can I use an eval if statement to create a new field based on a value?

Path Finder

I would like to use an if statement to create a new field based on a value. Something like if field1=0 and field2=0, then create new field with value of 1.

0 Karma
1 Solution

Builder

Path Finder

If you want to use case statement this may helps

search | eval newfield=case(field1=field2,1,1=1,0)

0 Karma

Influencer
| eval newfield=if(field1=0 and field2=0,1,null)

Builder

Path Finder

Perfect! thanks!

0 Karma