Splunk Commands : Everything to know about "eval" command

  Рет қаралды 78,300

Splunk & Machine Learning

Splunk & Machine Learning

Күн бұрын

In this video I have discussed about the "eval" command in details. I have discussed various supporting functions eval used in detail as well.
More about splunk eval :
docs.splunk.com/Documentation/...
you can download the data and query I have used from the below repo :
github.com/siddharthajuprod07...

Пікірлер: 77
@rajivaws6975
@rajivaws6975 4 жыл бұрын
hello sir...your tutorial helped me finding a job in splunk in reputed company so thanks a lot...can you plz let me know how would i get the eval query you shown in this video
@splunk_ml
@splunk_ml 4 жыл бұрын
Good to hear that Rajiv. In the video description you will find the github link for the materials used in this tutorial. Congratulations on your new job.
@gustavocastroortiz7645
@gustavocastroortiz7645 4 жыл бұрын
Great video content! Excuse me for chiming in, I am interested in your initial thoughts. Have you heard the talk about - Fanabraal Toned Tiraspol (do a search on google)? It is a smashing exclusive guide for sliming down naturally without exercise without the hard work. Ive heard some pretty good things about it and my close friend Aubrey finally got excellent success with it.
@afiyatkhan3319
@afiyatkhan3319 3 жыл бұрын
You are really really a very good instructor, you teach so nicely. Covering all points very well. So much respect for you Sir. Do you hv your any particular classes in regular basis I want to join that for advanced learning.
@Sugreev916
@Sugreev916 4 жыл бұрын
I have read some blog that mentioned "if we new to splunk needed direction on where to start, then always start with stats and eval commands"....This is one of the the Amazing Tutorial for eval commands !!!!! Awesome Explanation !!
@splunk_ml
@splunk_ml 4 жыл бұрын
Thank you 🙏
@srrkmm
@srrkmm 5 жыл бұрын
You are truly passionated about teaching or helping others . I respect you sir.
@snehalchikkodi7528
@snehalchikkodi7528 5 жыл бұрын
Really nice teaching...with detail example...thanku sir
@manasimeherkar9725
@manasimeherkar9725 3 жыл бұрын
Thank you for this video.it hepled me for my project. I m apperciated by my teams and managers. Keep it up.👍
@manigandanumapathy4840
@manigandanumapathy4840 5 жыл бұрын
Kudos to you!! Excellent teaching with clear examples👍👍🙏
@splunk_ml
@splunk_ml 5 жыл бұрын
Thank you Mani ☺️
@MathewsPious
@MathewsPious 5 жыл бұрын
Best Splunk tutorial I have seen till now. Thanks a lot.
@Sugreev916
@Sugreev916 5 жыл бұрын
Thank you so much !!!! Very detailed Explanation..............one of the best Video Tutorial I have ever seen for slunk!!!!!!!!!!!!! Keep Rocking !!!!
@splunk_ml
@splunk_ml 5 жыл бұрын
Thank you Sathya 👍... Please share this channel with your colleagues who work on Splunk.
@Sugreev916
@Sugreev916 5 жыл бұрын
@@splunk_ml Sure sir... already done
@antonyrajarathinam9976
@antonyrajarathinam9976 2 жыл бұрын
Awesome examples. Good job 👍🏻
@shivamr9352
@shivamr9352 2 жыл бұрын
Guru ko pranaam.
@mribin
@mribin 3 жыл бұрын
You are awesome. Great learning
@widodoboedijono9374
@widodoboedijono9374 2 жыл бұрын
Nice tutorial!! Really enjoying it!
@tabassumjain
@tabassumjain 5 жыл бұрын
This was a good quick course on eval, thanks! Keep the good work going!
@unnamveerendranath8112
@unnamveerendranath8112 5 жыл бұрын
Excellent videos
@bhavyashah1775
@bhavyashah1775 4 жыл бұрын
Amazing explanation for all the Commands and Functions!!
@kushagrajain6285
@kushagrajain6285 5 жыл бұрын
Thanks alot for the video... one of the best tutorial on splunk and explained with so much ease.
@splunk_ml
@splunk_ml 5 жыл бұрын
Thanks Kusharga :)
@wondwossenabebe3448
@wondwossenabebe3448 4 жыл бұрын
Wow! Very wonderful explanation. Easy to follow and understand . Thank you so much !! Do you have any videos about splunk ITSI and Splunk enterprise security. That would be a huge help. Thank you Again ..
@BlueTeamConsultingLLC
@BlueTeamConsultingLLC Жыл бұрын
eval is one of the most versatile commands Splunk has! Awesome coverage of it. #splunkyoutubers
@dipakrathod6394
@dipakrathod6394 Жыл бұрын
Its helpful..thank you
@rajenderprasad1193
@rajenderprasad1193 4 жыл бұрын
Amazing video..Thank you so much..
@rajenderprasad1193
@rajenderprasad1193 4 жыл бұрын
I created a lookup for my new field that I created.. but I am getting Assuming implicit file error when I use it.. I am not Admin.. I can't change conf file.. how can I get rid of this error. Pls help thank you
@venkatchimata5874
@venkatchimata5874 3 жыл бұрын
Hi, Please let me know if any support needed 6303692186
@RavindraKumarSG
@RavindraKumarSG 4 жыл бұрын
Kudos.. I am going to read all your tutorials. very beautiful. why dont you put them in udemy.
@SreejeshKarunakaran
@SreejeshKarunakaran 5 жыл бұрын
Brilliant tutorial. Thanks for doing this.
@splunk_ml
@splunk_ml 5 жыл бұрын
Thank you Sreejesh 👍
@habeebkaradan3426
@habeebkaradan3426 5 жыл бұрын
Very useful Siddhartha, keep your good work
@splunk_ml
@splunk_ml 5 жыл бұрын
Thanks Habeeb!!
@retrodiscoverer2056
@retrodiscoverer2056 3 ай бұрын
Great ! Thanks.
@donneakaleath9131
@donneakaleath9131 2 жыл бұрын
Thank you!
@daryoushjoobbani3125
@daryoushjoobbani3125 Жыл бұрын
Hi there, i have a question regarding the chart command. I am trying to execute a search splunk command that shows both the count and percentage of the count in one chart command: so here is an example of splunk command that currently only shows the count and the total count: source="xyz" http_status_code | chart count by path_template, http_status_code | addtotals col=t This command shows each count of the http_status_code (y axis) and the path_template (x axis) and showing the total of the counts of all the http_status_code. Now i need to add the percentage (count/total) of each count when i know the number of counts. e.g. 40 (5%) or something like that. How would i do that using chart? Thanks!
@ospavankumar
@ospavankumar 5 жыл бұрын
Very very interesting and well narrated the use cases, thanks alot bro... love with you n thanks for great help
@splunk_ml
@splunk_ml 5 жыл бұрын
Welcome 👍
@kankatalanerellu937
@kankatalanerellu937 5 жыл бұрын
Hi Best tutorial... thanks Can you make a vedio ...How to configure health check (monitoring Console) server in one server for distributed environment in splunk
@splunk_ml
@splunk_ml 5 жыл бұрын
Thank you for your feedback....I will definitely try to cover that but it may take some time as I have huge backlog of requests.
@balasadaksesh9536
@balasadaksesh9536 Жыл бұрын
Hi Siddarth, Its wonderful explanation, I would like to enroll to this course if are you providing online training on Advanced power user. Please share communication details for enrollment.
@manubelfort9383
@manubelfort9383 5 жыл бұрын
I truly adore your hard work in helping people who have started to know what Splunk is all about. I have a doubt while explaining the case, validate and if.. command. Why are you using double quotes for field values and single quotes for the field name?
@splunk_ml
@splunk_ml 5 жыл бұрын
Thank you. Regarding your query we need to that only when there are special characters in your field name.
@afiyatkhan3319
@afiyatkhan3319 3 жыл бұрын
You are really really a very good instructor, you teach so nicely. Covering all points very well. So much respect for you Sir. Do you hv your any particular classes in regular basis I want to join that for advanced learning.
@splunk_ml
@splunk_ml 3 жыл бұрын
Thank you Afiyat. I dont have any regular classes...whatever I know and will know about splunk or ML will be available in this channel only.
@afiyatkhan3319
@afiyatkhan3319 3 жыл бұрын
@@splunk_ml ya thanks for sharing your knowledge in this channel. I hv started learning splunk development. Can you plz explan the difference between stats and chart command. Both are confusing sometimes giving same results. And the most asked question in the interviews. And also plz explain about top command in brief.
@splunk_ml
@splunk_ml 3 жыл бұрын
yes , I will be covering that as well.
@afiyatkhan3319
@afiyatkhan3319 3 жыл бұрын
@@splunk_ml thanks again. Later going into avdance plz also try to cover python scripting part in your future videos if you are comfortable with it as now a days most of the companies demanding python scripting with splunk. If you are comfortable may I hv your email id? For any issues or doubts.
@splunk_ml
@splunk_ml 3 жыл бұрын
you can contact me via techiesid1985@gmail.com
@Sugreev916
@Sugreev916 4 жыл бұрын
Awesome Teaching !!! Can you take similar kind of session on Stats command
@splunk_ml
@splunk_ml 4 жыл бұрын
Yes that is already there in my todo list.
@venkatchimata5874
@venkatchimata5874 3 жыл бұрын
Hi, Please let me know if any support needed 6303692186
@le-manu298
@le-manu298 Жыл бұрын
@"Splunk & Machine Learning" - Thank you for the great lesson on "eval" command. My question is, these Fields and values you add using "eval" command, is there a way to make them permanent? After I logout and login again, they are back to the default value names. Thanks in advance
@splunk_ml
@splunk_ml Жыл бұрын
You can add them in props.conf as evel field extraction, so that it will be available search time. Please refer the below video, Its an old video when I didnt have access to proper recording device so you may have little difficulties , but content wise it should serve the purpose. kzbin.info/www/bejne/sHrNlnaPlst_eac
@brucekogami7962
@brucekogami7962 5 жыл бұрын
AAAwesome tutorial! Thanks!
@vishalkumarborse4115
@vishalkumarborse4115 3 жыл бұрын
Hi great tutorial could you please help me with one solution? Im using if function to find the field contains a name but user can insert that name in any case. Like i want to search Vishal but value could be vishal or VISHAL or vISHAL or Vishal. Presently im getting exact match for Vishal only. What if want result shouldn't be case sensitive?
@splunk_ml
@splunk_ml 3 жыл бұрын
you can use lower function like below, | makeresults count=2 | streamstats count | eval name = case(count=1,"VISHAL",count=2,"vISHAL") | eval lower_name = lower(name) | where lower_name = "vishal"
@manilamishra6901
@manilamishra6901 3 жыл бұрын
Hi Sir, I am a beginner at Splunk and I am stuck in a case. How can I get the User-agent from Request Heder in Splunk. I mean to ask what query should I write for this?? Please help !!
@splunk_ml
@splunk_ml 3 жыл бұрын
Can you please post this question to splunk community community.splunk.com/t5/Community/ct-p/en-us I am not fully understanding what is the exact requirement.
@shravanthielluri3408
@shravanthielluri3408 3 жыл бұрын
if we do "ps -ef | grep sh", few .sh scripts are running on servers, so if the .sh scripts are not running we need to get the alert, could you pls help me how I can write this
@splunk_ml
@splunk_ml 3 жыл бұрын
well you can index the output of "ps -ef | grep sh" in splunk in definite interval. Then just ceate alert based on those events.
@santhoshig7784
@santhoshig7784 4 жыл бұрын
Hi Sir.. thank you for the video.. one question .. in this , you have showed how to access free Linux console in Google cloud. I tried, But Google cloud is not accepting payment from most of the reputed banks in India. Could you please share an alternative option to use Linux server for free(like cloud Google). Though this question is slightly away from the topic, this is a showstopper for me to learn further. So could you pls suggest an alternative.
@splunk_ml
@splunk_ml 4 жыл бұрын
Ideally it should work. Even I am based in India. You can try to see AWS cloud...check if they have similar plans.
@vijaykumar-yq7sf
@vijaykumar-yq7sf 3 жыл бұрын
Hello Sir, Would you kindly tell us, where to get Logfiles so that we can study splunk in more detail?
@splunk_ml
@splunk_ml 3 жыл бұрын
You can download the data from the below link, docs.splunk.com/Documentation/SplunkCloud/8.0.2006/SearchTutorial/GetthetutorialdataintoSplunk
@vijaykumar-yq7sf
@vijaykumar-yq7sf 3 жыл бұрын
Thank u very much
@venkatchimata5874
@venkatchimata5874 3 жыл бұрын
Hi, Please let me know if any support needed 6303692186
@hemnaathgovartan3668
@hemnaathgovartan3668 5 жыл бұрын
How to use like function when both the field values are true. eg Requirement is when both First_1 and Last_1 values are true it should display true for rest it should display false. When I use the below syntax it is throwing error. index=main sourcetype=csv | eval new_field = if( like ('first name', "First_1", 'Last name', "Last_1") "true", "false") | table "first name" "last name" new_field Error in 'eval' command: The expression is malformed. Expected ). The search job has failed due to an error. You may be able view the job in the Kindly let me know how to write a SPL query in this case.
@splunk_ml
@splunk_ml 5 жыл бұрын
Hi Hemnaath, It should be something like below, | makeresults | eval "first name" = "First_1", "last name" = "Last_1" | eval new_field = if( like ('first name', "First_1") AND like ('last name', "Last_1"), "true", "false") | table "first name" "last name" new_field Sid
@hemnaathgovartan3668
@hemnaathgovartan3668 5 жыл бұрын
@@splunk_ml thanks Sid, for making such a nice videos on SPL queries.
@dilipvedantam3355
@dilipvedantam3355 5 жыл бұрын
Can you give training one on one?
@splunk_ml
@splunk_ml 5 жыл бұрын
Hi Dilip, Currently I have some bandwidth issue but as I am getting this type of request very frequently I have to think how I can handle it efficiently. Sid
Splunk Commands : How to use different JSON functions with eval command- PART 1
20:00
Splunk Commands : Detail discussion on commands related to multivalue fields
34:24
Splunk & Machine Learning
Рет қаралды 20 М.
He tried to save his parking spot, instant karma
00:28
Zach King
Рет қаралды 23 МЛН
Каха инструкция по шашлыку
01:00
К-Media
Рет қаралды 8 МЛН
Китайка и Пчелка 10 серия😂😆
00:19
KITAYKA
Рет қаралды 2 МЛН
Splunk Basic : Everything to know about macros
24:44
Splunk & Machine Learning
Рет қаралды 15 М.
Splunk Knowledge Object: Detail discussion on Summary Index
51:18
Splunk & Machine Learning
Рет қаралды 24 М.
Splunk Knowledge Object : detail discussion on "data model"
50:34
Splunk & Machine Learning
Рет қаралды 49 М.
Splunk Commands : Discussion on tstats command
36:46
Splunk & Machine Learning
Рет қаралды 16 М.
Introduction to Splunk Forwarder Deployment Topology and Configure Universal Forwarder
35:53
Splunk Configuration Files : Search time field extraction
48:32
Splunk & Machine Learning
Рет қаралды 30 М.
Splunk commands : Detail discussion on timechart command
34:32
Splunk & Machine Learning
Рет қаралды 20 М.
Мечта Каждого Геймера
0:59
ЖЕЛЕЗНЫЙ КОРОЛЬ
Рет қаралды 1,1 МЛН
КОПИМ НА АЙФОН В ТГК АРСЕНИЙ СЭДГАПП🛒
0:59
Bluetooth Desert Eagle
0:27
ts blur
Рет қаралды 6 МЛН
МОЩНЕЕ ТВОЕГО ПК - iPad Pro M4 (feat. Brickspacer)
28:01
ЗЕ МАККЕРС
Рет қаралды 70 М.
Iphone or nokia
0:15
rishton vines😇
Рет қаралды 1,6 МЛН