Splunk Search

How to write an eval condition to replace a field ?

pavanae
Builder

I have a query which displays some tabular results and when a certain condition is matched for 2 field values I want to insert a new value to Field_A like below

If field_A="not registered" and field_B="PROVISIONING" for a list of hosts then I want to change the Field_A value from "not registered" to "registered but not monitored"

How can I write an eval condition to satisfy the above. I have some how managed to get a little further like below

| eval field_A=if(field_A=="not registered" AND field_B=="PROVISIONING")

Please complete the above part eval condition above if someone knows how to do it?

0 Karma
1 Solution

somesoni2
Revered Legend

How about this?

| eval field_A=if(field_A=="not registered" AND field_B=="PROVISIONING", "regiestred but not monitored", field_A)

View solution in original post

aalaa
Path Finder

hello , Please how can i create a condition in a search to replace an event with a name , even if this event does not exist at the moment

0 Karma

somesoni2
Revered Legend

How about this?

| eval field_A=if(field_A=="not registered" AND field_B=="PROVISIONING", "regiestred but not monitored", field_A)
Get Updates on the Splunk Community!

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...