Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Renaming extracted values

$
0
0
I have the following data: Code Area 1234.1234 ABC 9933.9933 DEF 6611.6611 GHI 8910.8910 ABC 8910.1111 ABC Query looks like the following: | inputlookup combined.csv | search Code=* | eval NewArea=case('AREA'="DEF","Opeth",'AREA'="GHI","Danzig") | table Code, NewArea New output Code Area 1234.1234 ABC 9933.9933 Opeth 6611.6611 Danzig 8910.8910 ABC 8910.1111 ABC What I also need to do, is if Code equals 8910.* rename it to "Tool" and if Code equals 1234.1234 rename it to "Gojira" Code Area 1234.1234 Gojira 9933.9933 Opeth 6611.6611 Danzig 8910.8910 Tool 8910.1111 Tool Is something like this possible?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>