Splunk Search

If/else conditional statements for search??

monicato
Path Finder

Is it possible to have an if else conditional statement in search? I'm creating a form with a drop-down list and depending on which option the user chooses, the results are calculated differently. I need something that will do

if $eventtype$="event1" then, calculate completion rate this way,

else, calculate completion rate another way

Can this be done? I have a form and this search will be in a

~Thanks!!

1 Solution

Ayn
Legend

What does your whole search look like, and how are you calculating things? Splunk has the eval command which either can be used by itself (| eval foo=if(eventtype="event1",somecalculation,someothercalculation)) or as part of some kind of stats command (| stats count(eval(someevalcondition)) for instance, replace with whatever statistical function you want). There's also case which lets you specify an arbitrary number of options rather than just the if statements 2 (either eventtype is this, or it isn't).

View solution in original post

Ayn
Legend

What does your whole search look like, and how are you calculating things? Splunk has the eval command which either can be used by itself (| eval foo=if(eventtype="event1",somecalculation,someothercalculation)) or as part of some kind of stats command (| stats count(eval(someevalcondition)) for instance, replace with whatever statistical function you want). There's also case which lets you specify an arbitrary number of options rather than just the if statements 2 (either eventtype is this, or it isn't).

Splunk_U
Path Finder

how to do that?

0 Karma

john
Communicator

You can try conditionalswitcher modules to switch your modules or searches on basis of user input.

0 Karma

monicato
Path Finder

ah thanks! I was looking for the if statement format! Thank you!

0 Karma
Get Updates on the Splunk Community!

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...