Hi All,
How can I do switch case for below values
{"XXX":["ABC"]} == ABC
{"XXX":[]} == NULL .
| eval Name=case(Name == "{"XXX":[]}", "NULL", Name == "{"XXX":["ABC"]}", "ABC" ) - This is not working.
Thanks in Advance.
Splunk uses C-style escape sequences in strings. Escape the inner quotation marks with a backslash:
| eval Name=case(Name == "{\"XXX\":[]}", "NULL", Name == "{\"XXX\":[\"ABC\"]}", "ABC" )
Splunk uses C-style escape sequences in strings. Escape the inner quotation marks with a backslash:
| eval Name=case(Name == "{\"XXX\":[]}", "NULL", Name == "{\"XXX\":[\"ABC\"]}", "ABC" )
Thank you. It works.