Splunk Search

Help with subsearch eval function with where clause

ND
Path Finder

Hi All,

I want help to use where clause in eval command:

below is lookup data:

ID  expense year

1     10          2021

2     20          2020

3     10          2021

4     30          2019

5     20          2020

eval a = sum(expense) by ID, year where ID IN(1,3)

eval b= sum(expense) by ID, year  where ID IN(2,4)

eval c= sum(expense) by ID, year where ID IN(1,2,3,4)  [excluding few ID's from the search]

 

can someone help me to get this. I tried join to have these values as a subsearch but not able to get it.

 

thanks.

 

Labels (4)
0 Karma
1 Solution

ND
Path Finder

@ITWhisperer  thanks for the solution. it solved my query.

View solution in original post

0 Karma

ND
Path Finder

@ITWhisperer  thanks for the solution. it solved my query.

0 Karma

mayurr98
Super Champion

Could you please paste the result of the output that you want?

The question doesn't make sense to me, when you say sum(expense) by ID, it means sum(expense) by distinct ID in splunk language and it will always be the value of expense as shown in the input table.

Please tell us the output result in tabular format that you want.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval group_a=if(ID IN (1,3),expense,null())
| eval group_b=if(ID IN (2,4),expense,null())
| eval group_c=if(ID IN (1,2,3,4),expense,null())
| stats sum(group_a) as a sum(group_b) as b sum(group_c) as c by year
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...