Splunk eval Command Equivalent

Hi,

My team is in process of moving from Splunk to Elk. Does Elk have an equivalent to Splunk's eval command?

Thanks !

Welcome to our community! :smiley:

No, but what sort of things do you do with this so we can suggest alternatives?

Runtime fields are similar in that they emit a new column of data

1 Like

Thanks Graham
Thats what I was looking for !