Splunk Search

help with CASE needed

damucka
Builder

I have the following example:

|makeresults | eval trigger=0|eval decision=case(trigger=1;[|savedsearch test|eval t=1|return $t];0)

producing an error:
Error in 'eval' command: The expression is malformed. Expected )

The intention is clear, I want to execute the savedsearch test under the condition of trigger=1.
Could you please advice what it throws an error?

Kind Regards,
Kamil

Tags (1)
0 Karma

damucka
Builder

sorry, it was an easy mistake. I am closing this question.

0 Karma

niketn
Legend

@damucka if you can please post the fixed query and accept the same as answer to assist others facing similar issue.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

damucka
Builder

Sure.
I changed it to if, also there should be == instead of =

|makeresults | eval trigger=0|eval decision=if(trigger==1,[|savedsearch test|eval t=1|return $t],0)
0 Karma
Get Updates on the Splunk Community!

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...