Splunk Search
Highlighted

Eval commands

Explorer

Does anyone know if you do a rex and create a new field could you use that field for the eval commands?

IE:
| rex field=_raw "ACTION:\s(?.*) RETURNCODE"
| eval desc = case (action = "100", "Successfully Deleted")
| table user host action desc

Anyone know??

0 Karma
Highlighted

Re: Eval commands

SplunkTrust
SplunkTrust

You definitely can. If the rex command is working correctly the field qould be created and be available to any subsequent command.

0 Karma
Highlighted

Re: Eval commands

Explorer

yes we can... once you have extracted the field you can impose any function on top of that..

index=testcore source=abc ctx "1015" "SNB" "USA" | rex field=raw "ctx+]=[(?P\d+)" | dedup ctxx
| eval desc = case (ctxx = "80000000", "Successfully Deleted")
| table sourcetype host ctxx desc

View solution in original post

0 Karma
Highlighted

Re: Eval commands

Explorer

That works.

0 Karma