Splunk Search

How to display a single error in multiple inputs?

Dayalss
Engager

Hi , 

I have a search query -

| search Region = EMEA
| eval Status=case(Statistic=0,"Green" ,
Statistic=2,"Red",
Statistic=1,"Blue",
1==1, " " )
| appendpipe [ stats count | eval Status="Black" | where count=0 | fields - count]
| stats latest(Status)

The region has 7 SOD status data i.e. red and green. ,The issue is if one sod is in red state it is still showing green status.

What I require is even if there is a single red status it has to be picked and not the green one , as I am using it in a dashboard.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

case function is evaluated left to right, so put your highest priority condition first

| eval Status=case(Statistic=2,"Red",
Statistic=1,"Blue",
Statistic=0,"Green" ,
1==1, " " )
0 Karma

Dayalss
Engager

Tried it , but still its showing green

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please share some sample events (anonymised as necessary) in a code block </> so we can see what you are dealing with.

0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...