Splunk Search

Conditional Statements

MHibbin
Influencer

Hi Splunkbase,

I was wondering if someone would be able to assist with a problem that I am trying to get my head around, I am not able to get the desired results. Here is my problem...

Say I have some events, for example:

Device Location Result
a123   loc1     0  
b123   loc1     100
c123   loc1     0
----   ----     ------
a456   loc2     0
b456   loc2     0

I would like to group these devices by location, and then output a value dependant on the following condition... If for any device in a single location, the result is "100" then the output value for the whole location (new field) will be 100, or if all the devices in a single location have a result of "0" then I would like to output 0 to the new field.

So my expected results would be something like:

Location Result
loc1     100
loc2     0

Or something to that effect.

Any thoughts/suggestions.

Regards,

Matt

Tags (3)
0 Karma
1 Solution

Stephen_Sorkin
Splunk Employee
Splunk Employee

Your best bet is to use stats. Here you may want to use max() as an aggregator.

For example, append to your search:

| stats max(Result) as Result by Location

You can always use eval. For example, if you only care about Result being exactly 100:

| stats max(eval(if(Result==100, 100, 0))) as Result by Location

View solution in original post

Stephen_Sorkin
Splunk Employee
Splunk Employee

Your best bet is to use stats. Here you may want to use max() as an aggregator.

For example, append to your search:

| stats max(Result) as Result by Location

You can always use eval. For example, if you only care about Result being exactly 100:

| stats max(eval(if(Result==100, 100, 0))) as Result by Location

MHibbin
Influencer

Ha! Always the simplest solution that I overlooked!

Thanks.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...