Hi @PaulaCom case() returns the value for the first condition that matches, then stops, it never combines conditions, which is why the "both true" scenario collapses into whichever branch is listed first. Your second attempt also has a syntax error: case(manager = "NULL") isn't valid (case needs condition/value pairs), and there's a missing comma before 1=1. You could try to build the individual flags first with if(), then combine them: | table cn manager accountExpires mail
| eval needManager=if(manager="NULL",1,0)
| eval needExpiry=if(match(accountExpires,"(never)"),1,0)
| eval action=case(
needManager=1 AND needExpiry=1,"Set expiry date and manager",
needManager=1,"Manager to be added to account",
needExpiry=1,"Apply Expiry Date",
1=1,"no action required")
| fields - needManager needExpiry This evaluates both conditions independently first, so you can test any combination (including both true) explicitly, rather than relying on case()'s single-match, first-true behaviour. 🌟 Did this answer help you? If so, please consider: Adding karma to show it was useful Marking it as the solution if it resolved your issue Commenting if you need any clarification Your feedback encourages the volunteers in this community to continue contributing.
... View more