Splunk Search

If statements inside search

Vip_Mark
Explorer

I am currently using an Input token called OS.

I have three values for the token:

     MAC 

     Windows

     Linux.

In my visualization I want to say: 

If OS = Mac . Then run this search.

If OS = Windows. Then Run this search

If OS = Linux. Then run this search.

 

I am aware that the EVAL command has decision logic built into it but I don't think that  it can handle sub searches inside the case. Any help is appreciated 🙂

Thank you,

Mark

Labels (4)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Is your input a dropdown? If so, set the value to be the search corresponding to the label and then use the token as (part of) your search

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...