Splunk Search

How to Build an If Statement based on if a field contains a string

katzr
Path Finder

For every record where the field Test contains the word "Please" - I want to replace the string with "This is a test", below is the logic I am applying and it is not working- I tried using case, like, and a changed from " to ' and = to == but I cannot get anything to work.

| eval Test=if(Test=="Please", "This is a test", Test)

0 Karma
1 Solution

somesoni2
SplunkTrust
SplunkTrust

Try like this

...| eval Test=if(match(Test,"Please"),"This is a test", Test)

The equal sign does the exact comparison (value should match exactly). Since you want to check for "contains", you can use match(Test,"Please") or like(Test,"%Please%").

View solution in original post

somesoni2
SplunkTrust
SplunkTrust

Try like this

...| eval Test=if(match(Test,"Please"),"This is a test", Test)

The equal sign does the exact comparison (value should match exactly). Since you want to check for "contains", you can use match(Test,"Please") or like(Test,"%Please%").

katzr
Path Finder

thank you this works!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

Happy CX Day, Splunk Community!

Happy CX Day, Splunk Community! CX stands for Customer Experience, and today, October 3rd, is CX Day — a ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...