SPLK-1002 · Question #128
In the following eval statement, what is the value of description if the status is 503? index=main | eval description=case(status==200, "OK", status==404, "Not found", status==500, "Internal Server…
The correct answer is A. The description field would contain no value. When no condition in a Splunk case() function matches the input value, the resulting field is assigned no value (null).
Question
In the following eval statement, what is the value of description if the status is 503? index=main | eval description=case(status==200, "OK", status==404, "Not found", status==500, "Internal Server Error")
Options
- AThe description field would contain no value.
- BThe description field would contain the value 0.
- CThe description field would contain the value "Internal Server Error".
- DThis statement would produce an error in Splunk because it is incomplete.
How the community answered
(32 responses)- A88% (28)
- B9% (3)
- D3% (1)
Why each option
When no condition in a Splunk case() function matches the input value, the resulting field is assigned no value (null).
The case() function evaluates each condition-value pair in order and returns the value for the first true match. Because status 503 does not match 200, 404, or 500, no branch is satisfied and the description field is left with no value (null), effectively omitting it from that event.
The case() function does not return a numeric 0 when no condition matches; it returns null, leaving the field empty rather than assigning a zero value.
Status 503 does not equal 500, so the 'Internal Server Error' condition evaluates to false and that branch is never triggered.
The case() statement is syntactically valid in Splunk; a default/else clause is optional, so the absence of one does not produce an error.
Concept tested: Splunk eval case() function with no matching condition
Source: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions
Topics
Community Discussion
No community discussion yet for this question.