Im trying to nullified data in "status" field for any value match as "InActive" based on accounttype . Appreciate help on appropriate SPL Thanks
accounttype status count
Human_Account Active 1333
Human_Account InActive 106
Generic_Account Active 50
Service_Account InActive 540
You can eval the field and define logic as per your requirement. Please check below search.
YOUR_SEARCH
| eval status=if(accounttype=="Human_Account" and status="InActive",null(),status)
Here, I have nullified status column if account type is Human_Account and status is InActive.
You can change if condition as per your requirement.
My Sample Search :
| makeresults | eval _raw="accounttype,status,count
Human_Account,Active,1333
Human_Account,InActive,106
Generic_Account,Active,50
Service_Account,InActive,540" | multikv forceheader=1
|table accounttype status count
| rename comment as "Upto now is for sample data only"
| eval status=if(accounttype=="Human_Account" and status="InActive",null(),status)
Thanks
KV
If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.
You can eval the field and define logic as per your requirement. Please check below search.
YOUR_SEARCH
| eval status=if(accounttype=="Human_Account" and status="InActive",null(),status)
Here, I have nullified status column if account type is Human_Account and status is InActive.
You can change if condition as per your requirement.
My Sample Search :
| makeresults | eval _raw="accounttype,status,count
Human_Account,Active,1333
Human_Account,InActive,106
Generic_Account,Active,50
Service_Account,InActive,540" | multikv forceheader=1
|table accounttype status count
| rename comment as "Upto now is for sample data only"
| eval status=if(accounttype=="Human_Account" and status="InActive",null(),status)
Thanks
KV
If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.
@kamlesh_vaghela thanks so much sir - the SPL works as intended