Comparing Values

Comparing Values

Summary

This three-hour course is for power users who want to learn how to compare field values using eval functions and eval expressions. Topics will focus on using the comparison and conditional functions of the eval command, and using eval expressions with the fieldformat and where commands.

Description

  • Using eval to Compare
  • Filtering with where

 

Duration

3 hours

Objectives

Topic 1 – Using eval to Compare

  • Understand the eval command
  • Explain evaluation functions
  • Identify and use comparison and conditional functions
  • Use the fieldformat command to format field values

Topic 2 – Filtering with where

  • Use the where command to filter results
  • Use wildcards with the where command
  • Filter fields with the information functions, isnull and isnotnull

Topic 3 – Using Fields in Searches

  • Use fields correctly in basic searches
  • Use fields with operators
  • Use the rename command
  • Use the fields command to improve search performance

Topic 4 – Comparing Temporary versus Persistent Fields

  • Differentiate between temporary and persistent fields
  • Create temporary fields with the eval command
  • Extract temporary fields with the erex and rex commands

Topic 5 – Enriching Data

  • Understand how fields from lookups, calculated fields, field aliases, and field extractions enrich data

Audience

Search Experts Knowledge Managers

Prerequisites

To be successful, students should have a solid understanding of the following:

  • How Splunk works
  • Creating Search queries

 

Additional Notes

Individuals who enroll in this class will also be enrolled in an (eLearning with Labs) component. Completion of labs and quizzes is required in order to receive proof of completion.

Onsite Training

For groups of three or more

Request Quote

Public Training

AMER Brazil Time - Virtual (Portuguese)

  • Confirmed
    9:00 AM - 12:00 PM BRT
    $ 500.00 USD
  • Confirmed
    9:00 AM - 12:00 PM BRT
    $ 500.00 USD
  • Confirmed
    9:00 AM - 12:00 PM BRT
    $ 500.00 USD
  • Confirmed
    9:00 AM - 12:00 PM BRT
    $ 500.00 USD
  • Confirmed
    9:00 AM - 12:00 PM BRT
    $ 500.00 USD
  • Confirmed
    9:00 AM - 12:00 PM BRT
    $ 500.00 USD
  • Confirmed
    9:00 AM - 12:00 PM BRT
    $ 500.00 USD
  • Confirmed
    9:00 AM - 12:00 PM BRT
    $ 500.00 USD

AMER Pacific Time - Virtual

  • Confirmed
    9:00 AM - 12:00 PM PDT
    $ 500.00 USD
  • Confirmed
    9:00 AM - 12:00 PM PDT
    $ 500.00 USD

APAC Sydney - Virtual

  • 9:00 AM - 12:00 PM AEST
    $ 500.00 USD
  • 9:00 AM - 12:00 PM AEST
    $ 500.00 USD

AMER Eastern Time - Virtual

  • Confirmed
    9:00 AM - 12:00 PM EDT
    $ 500.00 USD
  • Confirmed
    9:00 AM - 12:00 PM EDT
    $ 500.00 USD
  • Confirmed
    9:00 AM - 12:00 PM EDT
    $ 500.00 USD
  • Confirmed
    2:00 PM - 5:00 PM EDT
    $ 500.00 USD
  • Confirmed
    9:00 AM - 12:00 PM EDT
    $ 500.00 USD

APAC Singapore - Virtual

  • Confirmed
    9:00 AM - 12:00 PM SGT
    $ 500.00 USD
  • Confirmed
    9:00 AM - 12:00 PM SGT
    $ 500.00 USD
  • Confirmed
    9:00 AM - 12:00 PM SGT
    $ 500.00 USD
  • Confirmed
    9:00 AM - 12:00 PM SGT
    $ 500.00 USD

EMEA Greenwhich Mean Time - Virtual

  • 9:00 AM - 12:00 PM BST
    $ 500.00 USD
  • 9:00 AM - 12:00 PM BST
    $ 500.00 USD

AMER Eastern Time - Virtual (Spanish)

  • Confirmed
    9:00 AM - 12:00 PM EDT
    $ 500.00 USD

Fast Lane Italia - Milano

  • 9:30 AM - 12:30 PM CEST
    $ 500.00 USD

EMEA UK Time - Virtual

  • Confirmed
    9:00 AM - 12:00 PM BST
    $ 500.00 USD

Don't see a date that works for you?

Request Class