Splunk Search

Case conidtion on the searches

xiaoyuew
Path Finder

My logs contain a field "A", i need to calculate a new field "B" based on the SLOT,
when A=a1 OR A=a2, THEN B=avg of these 2 types of searches
when A=a3 OR A=a4 or A=a5, Then B =avg of these 3 types of searches
when A=a6 OR A=a7 , Then B =avg of these 2 types of searches
...

How should i do this? Thanks.

Tags (2)
0 Karma

xiaoyuew
Path Finder

@Ayn

for example, i have the following 7 logs,

2011-DEC-17 slotid="Location-Maps-US-Sunnyvale" delta_msec="1487" seq="3"

2011-DEC-17 slotid="Location-Maps-US-MountainView" delta_msec="1445" seq="2"

2011-DEC-17 slotid="Location-Maps-US-SF" delta_msec="1465" seq="2"

2011-DEC-17 slotid="Location-Store-CA-MountainView" delta_msec="1445" seq="2"

2011-DEC-17 slotid="Location-Store-CA-SF" delta_msec="1245" seq="2"

2011-DEC-17 slotid="Location-Msg-CA-MountainView" delta_msec="1445" seq="2"

2011-DEC-17 slotid="Location-Msg-CA-SF" delta_msec="1245" seq="2"

i want to calculate a new field(avg_msec) based on the "slotid":
we would like to calculate an average for all logs matching "Location-Maps"
we would like to calculate an average for all logs matching "Location-Store"
we would like to calculate an average for all logs matching "Location-Msg"

0 Karma

Ayn
Legend

You should provide some more details on the searches to get real useful responses, however I imagine you will want to have a look at eval and its function case which handles precisely what it says. http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...