I have a rex statement that parses multiple events and extracts the servers and its state:, something like below.
index="index-name" "keyword" instance="https://jenkins-*com" |rex field=_raw "}\s(?\d[-+]?[0-9]*.?[0-9]+)"| dedup 1 instance
the above query returns as below
instance3 1.00 .... so on
I add eval statements after this query to check if specific instance and state is matched.
this works, but the eval command gets repeated for all the occurrences of "instances"., like the following.
Name state eval_output
instance1 1.00 yes
instance2 0.00 no
instance3 1.00 yes
But, what i would like to achieve is to break the looping, meaning after eval command is executed for all instances, i add another eval statement which just uses the output and not adding it to all instances. how can i achieve this? I have this problem while using svg app.
That's normal behavior. With some exceptions (like
stats), SPL commands are executed against each event fetched by the search. If you don't want the results of an
eval to be seen, use
fields - foo to get rid of a field.
That said, perhaps there's another way to solve your problem. If you'll explain what you're trying to accomplish we may be able to find another way to do it.
thanks for checking it.
So, here is what i am looking for.
|append [search index="index-name" probesuccess instance="https://teams-*" |rex field=raw "}\s(?\d[-+]?[0-9]*.?[0-9]+)"| dedup 1 instance]
| eval instance1= if((instance == "https://teams-instance1 AND stat == 1), "", "")
| eval instance2= if((instance == "https://teams-instance2 AND stat == 1), "", "")
| eval svg_viz = "
| table svg_viz
Here, svg_viz has to run only once after all check has been done replacing the variables in the svg definition. But what happens is that svg gets created for every event and i am not able to consolidate the checks.