Splunk Search

Eval statement based of 1 field using If

codedtech
Path Finder

I have a bunch of storage clusters that we monitor,  60% of the envrioment uses normal GB, the other 40% uses GiB.  I need to show all of the storage arrays in 1 report and normalize the storage to GB, and the only field that is different between the storage besides the array name is "storage vendor" .  I need to create an If statement if vendor is like "X"  run these evals 
|eval _GB_TiB = (((Capacity_GB)*1.1)/1024)*0.909495
| eval "Prov(TiB)" = (((prov_GB)*1.1)/1024)*0.909495
| eval "Written(TiB)" = ((((writtedGB)*1.1)/1024)*0.909495)/2

 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
How should Splunk distinguish those that use GB from those that use GiB?
---
If this reply helps you, Karma would be appreciated.
0 Karma

codedtech
Path Finder

I like to use an If or case statement ideally based of the vendor or storage array name.  

 

something along the lines like this

query|eval if(vendor="vendor 1(then  eval Capacity(TiB) = (((Capacity_GB)*1.1)/1024)*0.909495
| eval "provisioned (TiB)" = (((provisionedGB)*1.1)/1024)*0.909495
| eval "Written(TiB)" = ((((usedGB)*1.1)/1024)*0.909495)/2

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Perhaps this will help

... | eval Capacity = if(vendor="foo" OR vendor="bar", exact((GB*1.1)/1024)*0.909495), GB)
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...