Splunk Search
Highlighted

conditional switch in splunk

Engager

Hi,

I have a splunk query which reads a log file and returns a list of values to a chart. However I need to values to be more "readable".
e.g. output:
$#@VALUE_1 ===> ONE

$#@VALUE_2 ===> TWO

$#@VALUE_3 ===> THREE

is there a way to say "if the value is $VALUE1, then output "ONE", else if the value is $VALUE2 then output "TWO"?

I am not able to modify what is written to the actual log

Tags (2)
0 Karma
Highlighted

Re: conditional switch in splunk

Splunk Employee
Splunk Employee

You can use "eval"/"case" to create a new field with the desired value. This assumes those values are in the same existing field

... | eval new_field=case(old_field == "$_VALUE_1", "ONE", old_field == "$_VALUE_2", "TWO")

View solution in original post