use an eval, and a condition like : fieldA=if(condition is fulfilled, then use value in Other fieldB, else use the pre-existing value in fieldA)
< my search > | eval IP=if(host=="10.0.0.1",src_ip,IP)
use an eval, and a condition like : fieldA=if(condition is fulfilled, then use value in Other fieldB, else use the pre-existing value in fieldA)
< my search > | eval IP=if(host=="10.0.0.1",src_ip,IP)
Thank you yannK! That was very helpful!
I'm trying to do exactly the same thing, but no matter what the value of the Event field, the new field evaluates to the value of MedRepoCloneMergeTimemin and not "na" as expected.
| eval newfield=if(in(Event,"mock"), "na", MedRepoCloneMergeTimemin)
| eval newfield=if(Event == mock, "na", MedRepoCloneMergeTimemin)
What am I missing? thanks for any ideas.