If AVSResponse = x
, then I need to display "matched" in the dashboard report. Likewise, if I have more than 10 value to be matched. Kindly help how I can set up the ssearch. thanks
Have you tried if or case from http://docs.splunk.com/Documentation/Splunk/6.1/SearchReference/Commonevalfunctions
Eg:
... | eval description=case(error == 404, "Not found", error == 500, "Internal Server Error", error == 200, "OK")
Have you tried if or case from http://docs.splunk.com/Documentation/Splunk/6.1/SearchReference/Commonevalfunctions
Eg:
... | eval description=case(error == 404, "Not found", error == 500, "Internal Server Error", error == 200, "OK")
Looks great. Just tried something like -
index=iiii | eval cat=case(host == "aaaa", "customer", host == "bbbb", "customer") and it works.
Be sure to accept renjith.nair's answer of it worked for you. That way people can see what to do.
@ ddrillic & Renjith.nair , thanks alot for sharing your knowledge. Great support ! executed the query successfully .