Hey Splunkers,
I am not sure if this is possible or not but what i was trying to do is something like passing the values of search in the eval command to basically form a statement or an event .
So for example consider below search returns multiple users first name, last name and country details.
Now with that field values what i am trying to do is create a eval statement like below-
index=foo source=user_detail
|table first_name last_name country
|eval statement = My name is "$first_name $ $last_name$ and i come from $country$
|table statement
But this is not passing those field values to eval statement, so anyone knows if there is a way we can do this ?
Thanks.
Hi @ak9092,
let me understand: you want to concatenatethree fields value in only one, is it correct?
if this is your need, please try this:
index=foo source=user_detail
| eval statement="My name is ".first_name." ".last_name." and i come from ".country
| table statement
Ciao.
Giuseppe
Hi @ak9092,
let me understand: you want to concatenatethree fields value in only one, is it correct?
if this is your need, please try this:
index=foo source=user_detail
| eval statement="My name is ".first_name." ".last_name." and i come from ".country
| table statement
Ciao.
Giuseppe
That's exactly what I needed, Thanks much @gcusello
Hi @ak9092,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉