Splunk Search

Populate predefined field for found strings

subtrakt
Contributor

Good Day,

I'm attempting to create a label for different search responses.

Example:
if search 'A' finds error "500", Field B. is populated with "test1"
if search 'A' finds error "400", Field B. is populated with "test2"

and soo on.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could do something like this:

... | eval B = case(search finds error "500", "test1", search finds error "400", "test2)
0 Karma

subtrakt
Contributor

thanks. any idea how to tell it to only display if 400 are greater than 350 count?

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...