Hey Splunkers!
Please help me with the below query.
I have the below table, and i want to create a new column based on the existing column values:
Column1 | Column2 | Column3 | Result |
Apple | Grape | Cherry | Fruits |
Spinach | Potato | Raddish | Vegetables |
The Result column is the one Im looking to derive with the below query:
| eval Result = if(column1="Apple" OR column2="Grape" OR column3="Cherry" , "Fruits", column1="Spinach" OR column2="Potato" OR column3="Raddish" , "Vegetables",1==1, "Unknown")
However im getting an error, can someone please help?
Much appreciated.
Thanks!
Try this,
YOUR_SEARCH
|eval Result = case(Column1="Apple" OR Column2="Grape" OR Column3="Cherry", "Fruits", Column1="Spinach" OR Column2="Potato" OR Column3="Raddish" , "Vegetables",1==1, "Unknown")
Sample Search:
| makeresults | eval _raw="
Column1 Column2 Column3
Apple Grape Cherry
Spinach Potato Raddish"
| multikv forceheader=1
|eval Result = case(Column1="Apple" OR Column2="Grape" OR Column3="Cherry", "Fruits", Column1="Spinach" OR Column2="Potato" OR Column3="Raddish" , "Vegetables",1==1, "Unknown")
Try this,
YOUR_SEARCH
|eval Result = case(Column1="Apple" OR Column2="Grape" OR Column3="Cherry", "Fruits", Column1="Spinach" OR Column2="Potato" OR Column3="Raddish" , "Vegetables",1==1, "Unknown")
Sample Search:
| makeresults | eval _raw="
Column1 Column2 Column3
Apple Grape Cherry
Spinach Potato Raddish"
| multikv forceheader=1
|eval Result = case(Column1="Apple" OR Column2="Grape" OR Column3="Cherry", "Fruits", Column1="Spinach" OR Column2="Potato" OR Column3="Raddish" , "Vegetables",1==1, "Unknown")
"if" should be "case"