Splunk Search

How to use comparison operators in a search to match field value condition?

gajananh999
Contributor

Hello Everyone,

i want to check one condition in splunk and if that condition match and then i need to get those events who matches condition else result should be null

LAST < sysdate - (1/(2*24)) 

LAST is one field in splunk and can one help me out here.
for sysdate -(1/(2*24)) i have done eval tnow = now() | eval finalvalue=tnow-0.0208333333333333

so now i have to check the LAST < finalvalue

I have tried this

search string  |eval tnow = now()  | eval finalvalue=tnow-0.0208333333333333| eval Severity=if(LAST < finalvalue,NODE,null()) | table Severity,NODE

when i am doing this if condition doesn't match also it is creating table with first field as null.

Can anyone help me out here

Thanks

 

0 Karma
1 Solution

gajananh999
Contributor

Hello Everyone i have used where condition LAST > finalvalue

View solution in original post

0 Karma

gajananh999
Contributor

Hello Everyone i have used where condition LAST > finalvalue

0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...