Splunk Search

Correct syntax for condition

greggz
Communicator

Im trying to perform a condition based on 2 varibles, but I can't seem to get right the expression. I've been trying to chain the conditions, but it doesnt work. What's the equivalent of this:

<change>

            <condition value="volume"> 
                 <condition match=" $token$ != 1">
                    <set token="volume-details1">true</set>
                    <unset token="resptime-details1"></unset>
                    <unset token="error-details1"></unset>
                    <unset token="gctime-details1"></unset>
                    <unset token="thread-details1"></unset>
                    <unset token="connpool-details1"></unset>
                    <unset token="cpu-details1"></unset>
                    <unset token="memory-details1"></unset>
                    <unset token="disk-details1"></unset>
              </condition>
           </condition>

</change>

 <init>
    <set token="token">0</set>
</init>
0 Karma
1 Solution

kamlesh_vaghela
SplunkTrust
SplunkTrust

Hi @greggz,

As your condition is nested can you please try below conditions in your condition code?

 <condition match=" $value$=&quot;volume&quot; AND  $token$ != 1">

Thanks

View solution in original post

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

Hi @greggz,

As your condition is nested can you please try below conditions in your condition code?

 <condition match=" $value$=&quot;volume&quot; AND  $token$ != 1">

Thanks

0 Karma

greggz
Communicator

<condition match=" $token$ != 1"> .. This line works fine if it's not inside the Outer condition. So, it's not from that Im sure

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

oooh..

$token$ is not a input token.?... Can you please share your sample xml ?

0 Karma

greggz
Communicator

No. Token is a "global" token.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

okay.
I think I missed nested condition tag. Can you please try this?

<condition match=" $value$=&quot;volume&quot; AND  $token$ != 1">
0 Karma

greggz
Communicator

Marvelous. It works! Thanks. Update answer for me to mark it as correct. thanks

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

Answer updated
Please accept and upvote any comment which helped you.
Thanks

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...