Splunk Search

How to write an eval condition to replace a field ?

pavanae
Builder

I have a query which displays some tabular results and when a certain condition is matched for 2 field values I want to insert a new value to Field_A like below

If field_A="not registered" and field_B="PROVISIONING" for a list of hosts then I want to change the Field_A value from "not registered" to "registered but not monitored"

How can I write an eval condition to satisfy the above. I have some how managed to get a little further like below

| eval field_A=if(field_A=="not registered" AND field_B=="PROVISIONING")

Please complete the above part eval condition above if someone knows how to do it?

0 Karma
1 Solution

somesoni2
Revered Legend

How about this?

| eval field_A=if(field_A=="not registered" AND field_B=="PROVISIONING", "regiestred but not monitored", field_A)

View solution in original post

aalaa
Path Finder

hello , Please how can i create a condition in a search to replace an event with a name , even if this event does not exist at the moment

0 Karma

somesoni2
Revered Legend

How about this?

| eval field_A=if(field_A=="not registered" AND field_B=="PROVISIONING", "regiestred but not monitored", field_A)
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...