| loadjob savedsearch="nobody:splunk_fcr_evo:monitoring"
| table adt, FLOW, Date, NbRecordsOKFCR, Total, NbRecords, NBFile, NA1, NA2, NA3, CM, Alert
| where match(FLOW, "$Flow_token$") and match(adt, "$adt_token$") $filter_green_lights$
| fields adt FLOW Date NA1, NA2, NA3,CM, "Total" | sort adt, Date
What values do you have in your tokens?
Different values in TEXT, Duplicate values and special character ( / and _ ) only.
Its like this-
| Date | FLOW | adt |
| 01/01/2023 | A_1 | aa/b |
| 01/01/2023 | A_1 | aa/c |
| 01/01/2023 | A_1 | aad |
| 01/01/2023 | A_1 | aae |
| 01/01/2023 | A_1 | aa/f |
| 01/01/2023 | A_1 | aag |
| 01/01/2023 | A_1 | aah |
| 01/01/2023 | A_1 | aa/i |
| 01/01/2023 | A_1 | aaj |
| 02/01/2023 | A_1 | aa/b |
| 02/01/2023 | A_1 | aa/c |
| 02/01/2023 | A_1 | aad |
| 02/01/2023 | A_1 | aae |
| 02/01/2023 | A_1 | aa/f |
| 02/01/2023 | A_1 | aag |
| 02/01/2023 | A_1 | aah |
| 02/01/2023 | A_1 | aa/i |
| 02/01/2023 | A_1 | aaj |
| 01/01/2023 | FN | a |
| 01/01/2023 | FN | b |
| 01/01/2023 | FN | c |
| 01/01/2023 | FN | d |
| 01/01/2023 | FN | e |
| 01/01/2023 | FN | g |
| 01/01/2023 | FN | h |
| 01/01/2023 | FN | i |
| 02/01/2023 | FN | a |
| 02/01/2023 | FN | b |
| 02/01/2023 | FN | c |
| 02/01/2023 | FN | d |
| 02/01/2023 | FN | e |
| 02/01/2023 | FN | g |
| 02/01/2023 | FN | h |
| 02/01/2023 | FN | i |
You may have to escape the slash with a backslash e.g. 01\/01\/2023 although this is not a quantifier, for that you are looking for + or * or {1} for example. Please check all the values you have in your tokens.