Usage of Splunk EVAL Function : IF This function takes three arguments X,Y and Z. The first argument X must be a Boolean expression. When
Returns true if the event matches the search string X. Find below the skeleton of the usage of the function “searchmatch” with EVAL :
Usage of Splunk EVAL Function : CASE This function takes pairs of arguments X and Y. X arguments are Boolean expressions When the first X
Usage of Splunk EVAL Function : ABS is as follows : This Function takes the “Numeric Value” as an Input and returns its Absolute Value.