Splunk Search

If statement

Explorer

Hi
I am running search to get rating status in my report, not getting any result and getting error
" Error in 'eval' command: The expression is malformed. Expected ) " here is my search,

Thanks

"sourcetype="TicketAnalysis" | eval XYZ = if (Rating1 >="6", "Satisfied", if (Rating1 <="6" AND Rating1 >= "4" "Neutral", if (Rating1 < "4" AND Rating1 >= 1, "Dissatisfied","Unrated"))) "

Tags (1)

Explorer

eval Comment=if((FundCreditAmt=AckCreditAmt) AND (FundDebitAmt=AckDebitAmt) ,"MATCH","MISMATCH")

Path Finder

Is there any particular reason you wouldn't use case instead?

Builder
sourcetype="TicketAnalysis" | eval XYZ = if (Rating1 >="6", "Satisfied", if (Rating1 <="6" AND Rating1 >= "4" **,** "Neutral", if (Rating1 < "4" AND Rating1 >= 1, "Dissatisfied","Unrated")))

i think you missed a comma in second if statement . if (Rating1 <="6" AND Rating1 >= "4" , "Neutral"

Builder

🙂 you have an option to remove other from pie graph in a dashboard . append this
0
thisanswer may help you;;

0 Karma

Explorer

Thanks, this works now ,but if i select pie graph i am getting extra field other (1), do you have any idea why its coming only on pie graph ?

0 Karma