Splunk Search

If Else functionality to pick different subsearch

pbarbuto
Path Finder

Depending on what month it is I need to run a different sub-search.

index=foo source=bar
    [| inputlookup servers.csv where myfield="this" 
    | eval nowMonth=strftime(now(), "%m") 
    | where nowMonth=06
    | eval host=name
    | fields host] 
    [| inputlookup servers.csv where myfield="that" 
    | eval nowMonth=strftime(now(), "%m") 
    | where nowMonth!=06 
    | eval host=name
    | fields host]

So basically if its the current month I want to run the first inputlookup, and if its NOT the current month I want to run the 2nd inputlookup. is this doable?

Tags (1)
0 Karma

FrankVl
Ultra Champion

Think that can be done in one go, like this:

index=foo source=bar
     [| inputlookup servers.csv  
     | eval nowMonth=strftime(now(), "%m") 
     | eval choice = if(nowMonth="06","this","that")
     | where myfield=choice
     | eval host=name
     | fields host] 
0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...