Splunk Search

eval if clarification

bonnlbbelandres
Path Finder

I have a document field that opens a document if available and it displays "no document found" if there is no document available.
But i want to add something to the document field.

i want to have a checkpoint that says pass or fail. If PASS, it should display either "document available" or "no document found"
if FAIL, it should display "Try again"

so im thinking,
is "eval if command" capable with this?

like

|eval document = if (checkpoint == "pass", ??? , "Try again")

i wanted to make that question mark the document field that displays "document available" or "no document found"

is it possible?

Tags (1)
0 Karma
1 Solution

gokadroid
Motivator

Yes you can do that similar to my example below:

In my example below, abc is the new variable I create. processState is another variable which will have active or ft, on which I am checking for status. Based on active status, I use another variable cpuUsage which will have more than one kind of value and get assigned to abc. If status is not active then I put "NA"

|eval abc=if(processState="active", cpuUsage, "NA")

So similarly you can make your own case which should work fine.

View solution in original post

gokadroid
Motivator

Yes you can do that similar to my example below:

In my example below, abc is the new variable I create. processState is another variable which will have active or ft, on which I am checking for status. Based on active status, I use another variable cpuUsage which will have more than one kind of value and get assigned to abc. If status is not active then I put "NA"

|eval abc=if(processState="active", cpuUsage, "NA")

So similarly you can make your own case which should work fine.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...