Description
Certifications
This course is part of the following Certifications:
Prerequisites
To be successful, students should have a solid understanding of the following:
- How Splunk works
- Creating search queries
Course Objectives
- Using eval to Compare
- Filtering with where
Outline: Comparing Values (SCV)
Topic 1 – Using eval to Compare
- Understand the eval command
- Explain evaluation functions
- Identify and use comparison and conditional functions
- Use the fieldformat command to format field values
Topic 2 – Filtering with where
- Use the where command to filter results
- Use wildcards with the where command
- Filter fields with the information functions, isnull and isnotnull