Splunk Search

rex and eval

New Member

I have a rex statement that parses multiple events and extracts the servers and its state:, something like below.

index="index-name" "keyword" instance="https://jenkins-*com" |rex field=_raw "}\s(?\d[-+]?[0-9]*.?[0-9]+)"| dedup 1 instance

the above query returns as below
Name state
instance1 1.00
instance2 0.00
instance3 1.00 .... so on

I add eval statements after this query to check if specific instance and state is matched.

this works, but the eval command gets repeated for all the occurrences of "instances"., like the following.

Name state eval_output
instance1 1.00 yes
instance2 0.00 no
instance3 1.00 yes

But, what i would like to achieve is to break the looping, meaning after eval command is executed for all instances, i add another eval statement which just uses the output and not adding it to all instances. how can i achieve this? I have this problem while using svg app.

0 Karma

Re: rex and eval


That's normal behavior. With some exceptions (like addcoltotals and stats), SPL commands are executed against each event fetched by the search. If you don't want the results of an eval to be seen, use fields - foo to get rid of a field.

That said, perhaps there's another way to solve your problem. If you'll explain what you're trying to accomplish we may be able to find another way to do it.

If this reply helps you, an upvote would be appreciated.
0 Karma

Re: rex and eval

New Member

thanks for checking it.

So, here is what i am looking for.

| makeresults
|append [search index="index-name" probesuccess instance="https://teams-*" |rex field=raw "}\s(?\d[-+]?[0-9]*.?[0-9]+)"| dedup 1 instance]
| eval instance1= if((instance == "https://teams-instance1 AND stat == 1), "", "")
| eval instance2= if((instance == "https://teams-instance2 AND stat == 1), "", "")
| eval svg_viz = "


| table svg_viz

Here, svg_viz has to run only once after all check has been done replacing the variables in the svg definition. But what happens is that svg gets created for every event and i am not able to consolidate the checks.

0 Karma