Splunk Search

Want to replace the field value name

ramkyreddy
Explorer
Name sku kit
NAC-D-CDSK-DLS-05.90 NAC-D HJA-JEOE-DNDN-94.4.0


This my data, I want to replace  with NAC-D to ANT-P for multiple values
this is my search query

| eval sku = if(name=="",substr(kit,0,5),substr(name,0,5))
| eval sku=case(sku =="NAC-D","ANT-P ",sku =="DHV-K","ABD-U",true(),sku)



Labels (2)
0 Karma

ramkyreddy
Explorer

thanks,  I got expected  output

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ramkyreddy ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

gcusello
SplunkTrust
SplunkTrust

Hi @ramkyreddy,

what exactly is your requirement?

<your_search>
| eval sku = if(name="",substr(kit,0,5),substr(name,0,5))
| eval sku=case(sku="NAC-D","ANT-P",sku="DHV-K","ABD-U",true(),sku)

the search should work.

 Ciao.

giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...