Splunk Search

Usage suggestion for eval

brettcave
Builder

It would be great if "eval" could do multiple evaluations in a single command, in a similar way that "stats" can:

stats sum(someField) as "sumField" sum(otherField) as "sumOtherField"

and with eval:

... | eval field1=(eval statement) field2=(eval statement)

instead of | eval | eval | eval

Tags (2)
1 Solution

BobM
Builder

Yes it would but this isn't a question. I suggest you contact support asking for this as an enhancement request.

View solution in original post

BobM
Builder

Yes it would but this isn't a question. I suggest you contact support asking for this as an enhancement request.

brettcave
Builder

ok, sorry, thought this forum could be used for suggestions / feedback around ideas.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...