Splunk Commands : Everything to know about "eval" command

Поділитися
Вставка
  • Опубліковано 6 січ 2025

КОМЕНТАРІ •

  • @rajivaws6975
    @rajivaws6975 5 років тому +14

    hello sir...your tutorial helped me finding a job in splunk in reputed company so thanks a lot...can you plz let me know how would i get the eval query you shown in this video

    • @splunk_ml
      @splunk_ml  5 років тому +2

      Good to hear that Rajiv. In the video description you will find the github link for the materials used in this tutorial. Congratulations on your new job.

    • @gustavocastroortiz7645
      @gustavocastroortiz7645 4 роки тому

      Great video content! Excuse me for chiming in, I am interested in your initial thoughts. Have you heard the talk about - Fanabraal Toned Tiraspol (do a search on google)? It is a smashing exclusive guide for sliming down naturally without exercise without the hard work. Ive heard some pretty good things about it and my close friend Aubrey finally got excellent success with it.

    • @afiyatkhan3319
      @afiyatkhan3319 4 роки тому

      You are really really a very good instructor, you teach so nicely. Covering all points very well. So much respect for you Sir.
      Do you hv your any particular classes in regular basis I want to join that for advanced learning.

  • @Sugreev916
    @Sugreev916 5 років тому +1

    I have read some blog that mentioned "if we new to splunk needed direction on where to start, then always start with stats and eval commands"....This is one of the the Amazing Tutorial for eval commands !!!!! Awesome Explanation !!

  • @srrkmm
    @srrkmm 5 років тому +4

    You are truly passionated about teaching or helping others . I respect you sir.

  • @MathewsPious
    @MathewsPious 5 років тому +2

    Best Splunk tutorial I have seen till now. Thanks a lot.

  • @manasimeherkar9725
    @manasimeherkar9725 4 роки тому

    Thank you for this video.it hepled me for my project. I m apperciated by my teams and managers. Keep it up.👍

  • @Sugreev916
    @Sugreev916 5 років тому +1

    Thank you so much !!!! Very detailed Explanation..............one of the best Video Tutorial I have ever seen for slunk!!!!!!!!!!!!! Keep Rocking !!!!

    • @splunk_ml
      @splunk_ml  5 років тому

      Thank you Sathya 👍... Please share this channel with your colleagues who work on Splunk.

    • @Sugreev916
      @Sugreev916 5 років тому +1

      @@splunk_ml Sure sir... already done

  • @manigandanumapathy4840
    @manigandanumapathy4840 5 років тому +1

    Kudos to you!! Excellent teaching with clear examples👍👍🙏

    • @splunk_ml
      @splunk_ml  5 років тому

      Thank you Mani ☺️

  • @kushagrajain6285
    @kushagrajain6285 6 років тому +1

    Thanks alot for the video... one of the best tutorial on splunk and explained with so much ease.

  • @antonyrajarathinam9976
    @antonyrajarathinam9976 2 роки тому

    Awesome examples. Good job 👍🏻

  • @snehalchikkodi7528
    @snehalchikkodi7528 5 років тому

    Really nice teaching...with detail example...thanku sir

  • @BlueTeamConsultingLLC
    @BlueTeamConsultingLLC 2 роки тому

    eval is one of the most versatile commands Splunk has! Awesome coverage of it. #splunkyoutubers

  • @daryoushjoobbani3125
    @daryoushjoobbani3125 2 роки тому

    Hi there, i have a question regarding the chart command. I am trying to execute a search splunk command that shows both the count and percentage of the count in one chart command: so here is an example of splunk command that currently only shows the count and the total count: source="xyz" http_status_code | chart count by path_template, http_status_code | addtotals col=t This command shows each count of the http_status_code (y axis) and the path_template (x axis) and showing the total of the counts of all the http_status_code. Now i need to add the percentage (count/total) of each count when i know the number of counts. e.g. 40 (5%) or something like that. How would i do that using chart? Thanks!

  • @shivamr9352
    @shivamr9352 2 роки тому

    Guru ko pranaam.

  • @widodoboedijono9374
    @widodoboedijono9374 3 роки тому

    Nice tutorial!! Really enjoying it!

  • @bhavyashah1775
    @bhavyashah1775 5 років тому +1

    Amazing explanation for all the Commands and Functions!!

  • @tabassumjain
    @tabassumjain 6 років тому +1

    This was a good quick course on eval, thanks! Keep the good work going!

  • @le-manu298
    @le-manu298 2 роки тому

    @"Splunk & Machine Learning" - Thank you for the great lesson on "eval" command. My question is, these Fields and values you add using "eval" command, is there a way to make them permanent? After I logout and login again, they are back to the default value names. Thanks in advance

    • @splunk_ml
      @splunk_ml  2 роки тому

      You can add them in props.conf as evel field extraction, so that it will be available search time. Please refer the below video, Its an old video when I didnt have access to proper recording device so you may have little difficulties , but content wise it should serve the purpose.
      ua-cam.com/video/zIjeCYafLCE/v-deo.html

  • @mribin
    @mribin 3 роки тому

    You are awesome. Great learning

  • @afiyatkhan3319
    @afiyatkhan3319 4 роки тому +1

    You are really really a very good instructor, you teach so nicely. Covering all points very well. So much respect for you Sir.
    Do you hv your any particular classes in regular basis I want to join that for advanced learning.

    • @splunk_ml
      @splunk_ml  4 роки тому +2

      Thank you Afiyat. I dont have any regular classes...whatever I know and will know about splunk or ML will be available in this channel only.

    • @afiyatkhan3319
      @afiyatkhan3319 4 роки тому

      @@splunk_ml ya thanks for sharing your knowledge in this channel.
      I hv started learning splunk development.
      Can you plz explan the difference between stats and chart command. Both are confusing sometimes giving same results. And the most asked question in the interviews.
      And also plz explain about top command in brief.

    • @splunk_ml
      @splunk_ml  4 роки тому

      yes , I will be covering that as well.

    • @afiyatkhan3319
      @afiyatkhan3319 4 роки тому

      @@splunk_ml thanks again. Later going into avdance plz also try to cover python scripting part in your future videos if you are comfortable with it as now a days most of the companies demanding python scripting with splunk.
      If you are comfortable may I hv your email id? For any issues or doubts.

    • @splunk_ml
      @splunk_ml  4 роки тому

      you can contact me via techiesid1985@gmail.com

  • @habeebkaradan3426
    @habeebkaradan3426 6 років тому +1

    Very useful Siddhartha, keep your good work

  • @kankatalanerellu937
    @kankatalanerellu937 5 років тому +2

    Hi
    Best tutorial... thanks
    Can you make a vedio ...How to configure health check (monitoring Console) server in one server for distributed environment in splunk

    • @splunk_ml
      @splunk_ml  5 років тому

      Thank you for your feedback....I will definitely try to cover that but it may take some time as I have huge backlog of requests.

  • @shravanthielluri3408
    @shravanthielluri3408 4 роки тому

    if we do "ps -ef | grep sh", few .sh scripts are running on servers, so if the .sh scripts are not running we need to get the alert, could you pls help me how I can write this

    • @splunk_ml
      @splunk_ml  4 роки тому

      well you can index the output of "ps -ef | grep sh" in splunk in definite interval. Then just ceate alert based on those events.

  • @unnamveerendranath8112
    @unnamveerendranath8112 6 років тому +1

    Excellent videos

  • @manilamishra6901
    @manilamishra6901 3 роки тому

    Hi Sir,
    I am a beginner at Splunk and I am stuck in a case. How can I get the User-agent from Request Heder in Splunk. I mean to ask what query should I write for this??
    Please help !!

    • @splunk_ml
      @splunk_ml  3 роки тому +1

      Can you please post this question to splunk community community.splunk.com/t5/Community/ct-p/en-us
      I am not fully understanding what is the exact requirement.

  • @dipakrathod6394
    @dipakrathod6394 2 роки тому

    Its helpful..thank you

  • @wondwossenabebe3448
    @wondwossenabebe3448 5 років тому

    Wow! Very wonderful explanation. Easy to follow and understand . Thank you so much !! Do you have any videos about splunk ITSI and Splunk enterprise security. That would be a huge help. Thank you Again ..

  • @vishalkumarborse4115
    @vishalkumarborse4115 4 роки тому

    Hi great tutorial could you please help me with one solution? Im using if function to find the field contains a name but user can insert that name in any case. Like i want to search Vishal but value could be vishal or VISHAL or vISHAL or Vishal. Presently im getting exact match for Vishal only. What if want result shouldn't be case sensitive?

    • @splunk_ml
      @splunk_ml  4 роки тому

      you can use lower function like below,
      | makeresults count=2
      | streamstats count
      | eval name = case(count=1,"VISHAL",count=2,"vISHAL")
      | eval lower_name = lower(name)
      | where lower_name = "vishal"

  • @hemnaathgovartan3668
    @hemnaathgovartan3668 5 років тому

    How to use like function when both the field values are true. eg Requirement is when both First_1 and Last_1 values are true it should display true for rest it should display false. When I use the below syntax it is throwing error.
    index=main sourcetype=csv | eval new_field = if( like ('first name', "First_1", 'Last name', "Last_1") "true", "false") | table "first name" "last name" new_field
    Error in 'eval' command: The expression is malformed. Expected ).
    The search job has failed due to an error. You may be able view the job in the
    Kindly let me know how to write a SPL query in this case.

    • @splunk_ml
      @splunk_ml  5 років тому

      Hi Hemnaath,
      It should be something like below,
      | makeresults
      | eval "first name" = "First_1", "last name" = "Last_1"
      | eval new_field = if( like ('first name', "First_1") AND like ('last name', "Last_1"), "true", "false") | table "first name" "last name" new_field
      Sid

    • @hemnaathgovartan3668
      @hemnaathgovartan3668 5 років тому +1

      @@splunk_ml thanks Sid, for making such a nice videos on SPL queries.

  • @ospavankumar
    @ospavankumar 5 років тому

    Very very interesting and well narrated the use cases, thanks alot bro... love with you n thanks for great help

  • @balasadaksesh9536
    @balasadaksesh9536 2 роки тому

    Hi Siddarth, Its wonderful explanation, I would like to enroll to this course if are you providing online training on Advanced power user. Please share communication details for enrollment.

  • @Sugreev916
    @Sugreev916 5 років тому

    Awesome Teaching !!! Can you take similar kind of session on Stats command

    • @splunk_ml
      @splunk_ml  5 років тому +1

      Yes that is already there in my todo list.

    • @venkatchimata5874
      @venkatchimata5874 4 роки тому

      Hi, Please let me know if any support needed 6303692186

  • @retrodiscoverer2056
    @retrodiscoverer2056 10 місяців тому

    Great ! Thanks.

  • @donneakaleath9131
    @donneakaleath9131 2 роки тому

    Thank you!

  • @vijaykumar-yq7sf
    @vijaykumar-yq7sf 4 роки тому

    Hello Sir, Would you kindly tell us, where to get Logfiles so that we can study splunk in more detail?

    • @splunk_ml
      @splunk_ml  4 роки тому

      You can download the data from the below link,
      docs.splunk.com/Documentation/SplunkCloud/8.0.2006/SearchTutorial/GetthetutorialdataintoSplunk

    • @vijaykumar-yq7sf
      @vijaykumar-yq7sf 4 роки тому

      Thank u very much

    • @venkatchimata5874
      @venkatchimata5874 4 роки тому

      Hi, Please let me know if any support needed 6303692186

  • @RavindraKumarSG
    @RavindraKumarSG 5 років тому

    Kudos.. I am going to read all your tutorials. very beautiful. why dont you put them in udemy.

  • @SreejeshKarunakaran
    @SreejeshKarunakaran 5 років тому +1

    Brilliant tutorial. Thanks for doing this.

    • @splunk_ml
      @splunk_ml  5 років тому

      Thank you Sreejesh 👍

  • @manubelfort9383
    @manubelfort9383 5 років тому

    I truly adore your hard work in helping people who have started to know what Splunk is all about. I have a doubt while explaining the case, validate and if.. command. Why are you using double quotes for field values and single quotes for the field name?

    • @splunk_ml
      @splunk_ml  5 років тому +1

      Thank you. Regarding your query we need to that only when there are special characters in your field name.

  • @santhoshig7784
    @santhoshig7784 5 років тому

    Hi Sir.. thank you for the video.. one question .. in this , you have showed how to access free Linux console in Google cloud. I tried, But Google cloud is not accepting payment from most of the reputed banks in India. Could you please share an alternative option to use Linux server for free(like cloud Google). Though this question is slightly away from the topic, this is a showstopper for me to learn further. So could you pls suggest an alternative.

    • @splunk_ml
      @splunk_ml  5 років тому

      Ideally it should work. Even I am based in India. You can try to see AWS cloud...check if they have similar plans.

  • @rajenderprasad1193
    @rajenderprasad1193 4 роки тому

    Amazing video..Thank you so much..

    • @rajenderprasad1193
      @rajenderprasad1193 4 роки тому

      I created a lookup for my new field that I created.. but I am getting Assuming implicit file error when I use it.. I am not Admin.. I can't change conf file.. how can I get rid of this error. Pls help thank you

    • @venkatchimata5874
      @venkatchimata5874 4 роки тому

      Hi, Please let me know if any support needed 6303692186

  • @dilipvedantam3355
    @dilipvedantam3355 5 років тому

    Can you give training one on one?

    • @splunk_ml
      @splunk_ml  5 років тому +2

      Hi Dilip,
      Currently I have some bandwidth issue but as I am getting this type of request very frequently I have to think how I can handle it efficiently.
      Sid

  • @brucekogami7962
    @brucekogami7962 5 років тому

    AAAwesome tutorial! Thanks!