Splunk eval Command Equivalent


My team is in process of moving from Splunk to Elk. Does Elk have an equivalent to Splunk's eval command?

Thanks !

Welcome to our community! :smiley:

No, but what sort of things do you do with this so we can suggest alternatives?

Runtime fields are similar in that they emit a new column of data

1 Like

Thanks Graham
Thats what I was looking for !

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.