Hey Splunkers!
Please help me with the below query.
I have the below table, and i want to create a new column based on the existing column values:
| Column1 | Column2 | Column3 | Result | 
| Apple | Grape | Cherry | Fruits | 
| Spinach | Potato | Raddish | Vegetables | 
The Result column is the one Im looking to derive with the below query:
| eval Result = if(column1="Apple" OR column2="Grape" OR column3="Cherry" , "Fruits", column1="Spinach" OR column2="Potato" OR column3="Raddish" , "Vegetables",1==1, "Unknown")
However im getting an error, can someone please help?
Much appreciated.
Thanks!
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		
Try this,
YOUR_SEARCH
|eval Result = case(Column1="Apple" OR Column2="Grape" OR Column3="Cherry", "Fruits", Column1="Spinach" OR Column2="Potato" OR Column3="Raddish" , "Vegetables",1==1, "Unknown")
Sample Search:
| makeresults | eval _raw="
Column1	Column2	Column3
Apple	Grape	Cherry
Spinach	Potato	Raddish"
| multikv forceheader=1
|eval Result = case(Column1="Apple" OR Column2="Grape" OR Column3="Cherry", "Fruits", Column1="Spinach" OR Column2="Potato" OR Column3="Raddish" , "Vegetables",1==1, "Unknown")
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		
Try this,
YOUR_SEARCH
|eval Result = case(Column1="Apple" OR Column2="Grape" OR Column3="Cherry", "Fruits", Column1="Spinach" OR Column2="Potato" OR Column3="Raddish" , "Vegetables",1==1, "Unknown")
Sample Search:
| makeresults | eval _raw="
Column1	Column2	Column3
Apple	Grape	Cherry
Spinach	Potato	Raddish"
| multikv forceheader=1
|eval Result = case(Column1="Apple" OR Column2="Grape" OR Column3="Cherry", "Fruits", Column1="Spinach" OR Column2="Potato" OR Column3="Raddish" , "Vegetables",1==1, "Unknown")
 
		
		
		
		
		
	
			
		
		
			
					
		"if" should be "case"
