Hello,
Novice, but getting better. I am searching the Internet, Splunk Docs, and Splunk Answers for an answer. Meanwhile, I figured to post my issue.
After the general search commands (index, sourcetype, etc.) I want to perform branching to different SPL commands based on the value of a field.
For example in pseudo code.
if process=snmpd
(| rex message=(blah, blah, blah)
| stats count(process), blah, blah, blah)
if process=sudo
(| rex message=(blah, blah, blah)
| stats count(process), blah, blah, blah)
etc., etc.,.....
I'm figuring this will be a combination of where, eval, case. However,I haven't figured out which one or combinations this would be.
I will continue to research and test. And any guidance or direction is appreciated.
Thanks in advance and God bless,
Genesius
... View more