Splunk Search

Number of Conditions in case() Statement

michaelsplunk1
Path Finder

Is there a limit to the number of conditions we can use in a case() statement?

I've reached a point where my ORs and ANDs are no longer being highlighted syntactically and neither are my parenthesis being highlighted with their corresponding opening/closing counterpart when I move the cursor one space beyond one.

Thank you!

gcusello
SplunkTrust
SplunkTrust

Hi @michaelsplunk1 ,

for my knowledge, there isn't any limit to the conditions in a case statement, but there'a limit to the lenght of a search caused not by Splunk (that has no limits) but by the browser.

In this case you can create your search outside Splunk, save it as a savedsearch and execute it using a command like | savedsearch yoursavedsearchname or using a macro.

About highlighting, be sure that there isn't any error in parenthesis and quotes.

Ciao.

Giuseppe

0 Karma

wkim20
Engager

I too have this same issue, @splunk / splunk team any response to this?  i am having the issue to the point where my conditions are not being met and it defaults to another value defined in the case statement condition but the field it is looking does not have the matching value.  

0 Karma

PrewinThomas
Motivator

@wkim20 

If none of the conditions in a Splunk case() statement are met, it will return the value specified for the default condition.
Can you share your query here, so that we can have a look.

Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

wkim20
Engager

only thing i did was to make sure the spaces were available in the query which were updated in the calc metrics.  Its just odd this had to be done this way...syntactically it was not wrong nor did Splunk flag as an error when running the query.  just odd overall on behavior of this tool and a bit mindful going forward

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...