Splunk Search

Eval Case Statement not working

lorellpascual
New Member

Not sure why the below is not working.

index=www_kinesis rtData.tag=pageviewTag | eval marketing_channel=case(rtData.referralUrl=="https://www.google.com/", "Natural Search", 1=1, "Direct Load") | table sessionId, marketing_channel, rtData.referralUrl

All I basically want is, if my rtData.referralUrl= https://www.google.com/ to output "Natural Search". For some reason I've done equals and I've tried even case match, and I'm still not returning "Natural Search", even though my referralUrl is clearly https://www.google.com/

Tags (2)
0 Karma
1 Solution

somesoni2
Revered Legend

The field name you used in eval contains special characters (dot) so they need to be enclosed within single quotes (this is applicable for eval and where commands). Try this

index=www_kinesis rtData.tag=pageviewTag | eval marketing_channel=case('rtData.referralUrl'=="https://www.google.com/", "Natural Search", 1=1, "Direct Load") | table sessionId, marketing_channel, rtData.referralUrl

View solution in original post

somesoni2
Revered Legend

The field name you used in eval contains special characters (dot) so they need to be enclosed within single quotes (this is applicable for eval and where commands). Try this

index=www_kinesis rtData.tag=pageviewTag | eval marketing_channel=case('rtData.referralUrl'=="https://www.google.com/", "Natural Search", 1=1, "Direct Load") | table sessionId, marketing_channel, rtData.referralUrl
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...