Splunk Search

Can you help me check multiple conditions in Splunk?

darshana2511
New Member

I have to check multiple conditions like if Auth = "PASS" and Basc = "PASS" and RReg = "PASS" then result ="PASS" else if anyone one of the condition as Fail then result = "Fail". How can I check this condition in splunk.

0 Karma

renjith_nair
Legend

@darshana2511,

Did you try this and what's missing from that?

eval result=if(Auth="PASS" AND Basc="PASS" AND RReg="PASS","PASS","Fail")
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...