nerdexam
Splunk

SPLK-1002 · Question #128

In the following eval statement, what is the value of description if the status is 503? index=main | eval description=case(status==200, "OK", status==404, "Not found", status==500, "Internal Server…

The correct answer is A. The description field would contain no value. When no condition in a Splunk case() function matches the input value, the resulting field is assigned no value (null).

Creating Field Aliases and Calculated Fields

Question

In the following eval statement, what is the value of description if the status is 503? index=main | eval description=case(status==200, "OK", status==404, "Not found", status==500, "Internal Server Error")

Options

  • AThe description field would contain no value.
  • BThe description field would contain the value 0.
  • CThe description field would contain the value "Internal Server Error".
  • DThis statement would produce an error in Splunk because it is incomplete.

How the community answered

(32 responses)
  • A
    88% (28)
  • B
    9% (3)
  • D
    3% (1)

Why each option

When no condition in a Splunk case() function matches the input value, the resulting field is assigned no value (null).

AThe description field would contain no value.Correct

The case() function evaluates each condition-value pair in order and returns the value for the first true match. Because status 503 does not match 200, 404, or 500, no branch is satisfied and the description field is left with no value (null), effectively omitting it from that event.

BThe description field would contain the value 0.

The case() function does not return a numeric 0 when no condition matches; it returns null, leaving the field empty rather than assigning a zero value.

CThe description field would contain the value "Internal Server Error".

Status 503 does not equal 500, so the 'Internal Server Error' condition evaluates to false and that branch is never triggered.

DThis statement would produce an error in Splunk because it is incomplete.

The case() statement is syntactically valid in Splunk; a default/else clause is optional, so the absence of one does not produce an error.

Concept tested: Splunk eval case() function with no matching condition

Source: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions

Topics

#eval command#case function#conditional logic#calculated fields

Community Discussion

No community discussion yet for this question.

Full SPLK-1002 Practice