Splunk Search

eval command help

yosplunksunny
New Member

Hi All,

Need help to get the values from multi field value. We have a field name "properties.targetResources{}.displayName" which has the multiple field value. Now when we have the field "operationName"="Add member to role completed (PIM activation) then we need to have the new field let's say "dest" field should pick 3rd value from field "properties.targetResources{}.displayName" . And when operationName = Add member to role request denied (PIM activation) then "dest" field should pick value 4th from field "properties.targetResources{}.displayName" .

Splunk search for single field mvindex is working fine

sourcetype="amdl:aadal:audit"  operationName="Add member to role completed (PIM activation)" | eval dest = case(operationName=="Add member to role completed (PIM activation)", mvindex('properties.targetResources{}.displayName',3))  | table dest

Splunk search for mutiple field value is not working fine

sourcetype="amdl:aadal:audit"  operationName=* | eval dest = if(case(operationName=="Add member to role completed (PIM activation)", mvindex('properties.targetResources{}.displayName',3)),  case(operationName = Add member to role request denied (PIM activation)
, mvindex('properties.targetResources{}.displayName',4))  | table dest

In this case eval is written wrong , need to fix this .

Thanks in advance

0 Karma
1 Solution

renjith_nair
SplunkTrust
SplunkTrust

@yosplunksunny,

Please refer to the usage of case and try below

    sourcetype="amdl:aadal:audit"  operationName=* 
   | eval dest =  case(operationName=="Add member to role completed (PIM activation)",mvindex('properties.targetResources{}.displayName',3)  
                       ,operationName = "Add member to role request denied (PIM activation)" mvindex('properties.targetResources{}.displayName',4),
                       ,true(),"Your default value"
                     )
  |table dest
Happy Splunking!

View solution in original post

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

@yosplunksunny,

Please refer to the usage of case and try below

    sourcetype="amdl:aadal:audit"  operationName=* 
   | eval dest =  case(operationName=="Add member to role completed (PIM activation)",mvindex('properties.targetResources{}.displayName',3)  
                       ,operationName = "Add member to role request denied (PIM activation)" mvindex('properties.targetResources{}.displayName',4),
                       ,true(),"Your default value"
                     )
  |table dest
Happy Splunking!
0 Karma
Get Updates on the Splunk Community!

Index This | Why do they call it hyper text?

November 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

State of Splunk Careers 2023: Career Resilience and the Continued Value of Splunk

For the past three years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

The Great Resilience Quest: 9th Leaderboard Update

The ninth leaderboard update (11.9-11.22) for The Great Resilience Quest is out >> Kudos to all the ...