Splunk Search

how to use a wild card in if condition in eval?

pavanae
Builder

I have an eval condition as below which is working good.

| eval Project=if(app=="abc_def_123", "XYZ", "ZXT")

Now If I have given a wild card as shown below it's not working. How can I apply the wild card as shown below and get the required results?

| eval Project=if(app=="abc_*", "XYZ", "ZXT")
0 Karma

woodcock
Esteemed Legend

You cannot; you must use something else like like or match or searchmatch like this:

... | eval Project=if(match(app, "^abc_"), "XYZ", "ZXT")
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...