hi All,
can someone help on the splunk search eval condition based on below scenario using fields
Actualstarttime and job_start_by
if job_start_by<= Actualstarttime
return "GREEN / STARTED ON TIME"
else:
return "AMBER / STARTED LATE"
else:
if now <= Actualstarttime
return "EARLY / NO DATA"
else:
return "RED / START SLA BREACH"
if now > Actualstarttime
return "RED / END SLA BREACH"
else:
return "BLUE / RUNNING"
All time fields are assumed to be in epoch time, i.e. number of seconds since the beginning of 1970.
| eval start_time = if (job_start_by<= Actualstarttime, "GREEN / STARTED ON TIME", "AMBER / STARTED LATE")
| eval early_red = if (now() <= Actualstarttime, "EARLY / NO DATA", "RED / START SLA BREACH")
| eval red_blue = if (now() > Actualstarttime, "RED / END SLA BREACH", "BLUE / RUNNING")