Splunk Search

Eval Case Statement not working

lorellpascual
New Member

Not sure why the below is not working.

index=www_kinesis rtData.tag=pageviewTag | eval marketing_channel=case(rtData.referralUrl=="https://www.google.com/", "Natural Search", 1=1, "Direct Load") | table sessionId, marketing_channel, rtData.referralUrl

All I basically want is, if my rtData.referralUrl= https://www.google.com/ to output "Natural Search". For some reason I've done equals and I've tried even case match, and I'm still not returning "Natural Search", even though my referralUrl is clearly https://www.google.com/

Tags (2)
0 Karma
1 Solution

somesoni2
Revered Legend

The field name you used in eval contains special characters (dot) so they need to be enclosed within single quotes (this is applicable for eval and where commands). Try this

index=www_kinesis rtData.tag=pageviewTag | eval marketing_channel=case('rtData.referralUrl'=="https://www.google.com/", "Natural Search", 1=1, "Direct Load") | table sessionId, marketing_channel, rtData.referralUrl

View solution in original post

somesoni2
Revered Legend

The field name you used in eval contains special characters (dot) so they need to be enclosed within single quotes (this is applicable for eval and where commands). Try this

index=www_kinesis rtData.tag=pageviewTag | eval marketing_channel=case('rtData.referralUrl'=="https://www.google.com/", "Natural Search", 1=1, "Direct Load") | table sessionId, marketing_channel, rtData.referralUrl
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...