Good morning everyone,
This is my first search:
index=test_vpn toto_VPN_Role="AU_GUE_WEB"
|collecte eval=if(action = success, "No", "Yes") | table toto_VPN_Role collecte
and my second research:
index="app_gue"
|eval collecte=if(tag = success, "No", "Yes") | table index collecte
I would like to combine the two researches into one, is that possible?
thanks,
Hello,
The best syntax it's:
index=test_vpn OR index=app_gue toto_VPN_Role="AU_GUE_WEB"
Hello,
The best syntax it's:
index=test_vpn OR index=app_gue toto_VPN_Role="AU_GUE_WEB"
Hello,
It works, but I only get the events from the app_gue index but not the events of toto_vpn index .
Hi
Try this
(index=test_vpn toto_VPN_Role="AU_GUE_WEB") OR (index="app_gue")
| eval collecte =if((action == "success") OR (tag == "success"), "No", "Yes")
| table toto_VPN_Role index collecte
Hello @vnravikumar
It works, but I only get the events from the app_gue index but not the events of toto_vpn index .
its toto_vpn
or test_vpn
?
sorry, it's test_vpn.
Please check that index is having data for the selected time range.
For the same time range, this search works:
index=test_vpn toto_VPN_Role="AU_GUE_WEB"
|collecte eval=if(action = success, "No", "Yes") | table toto_VPN_Role collecte
check this |collecte eval=if(action = success, "No", "Yes")
or | eval collecte =if(action = success, "No", "Yes")
it's :
| eval collecte =if(action = success, "No", "Yes")
(index=test_vpn toto_VPN_Role="AU_GUE_WEB") OR (index="app_gue")
| eval collecte =if((action == "success") OR (tag == "success"), "No", "Yes")
it's the same, not event of : (index=test_vpn toto_VPN_Role="AU_GUE_WEB")