| loadjob savedsearch="nobody:splunk_fcr_evo:monitoring"
| table adt, FLOW, Date, NbRecordsOKFCR, Total, NbRecords, NBFile, NA1, NA2, NA3, CM, Alert
| where match(FLOW, "$Flow_token$") and match(adt, "$adt_token$") $filter_green_lights$
| fields adt FLOW Date NA1, NA2, NA3,CM, "Total" | sort adt, Date
What values do you have in your tokens?
Different values in TEXT, Duplicate values and special character ( / and _ ) only.
Its like this-
Date | FLOW | adt |
01/01/2023 | A_1 | aa/b |
01/01/2023 | A_1 | aa/c |
01/01/2023 | A_1 | aad |
01/01/2023 | A_1 | aae |
01/01/2023 | A_1 | aa/f |
01/01/2023 | A_1 | aag |
01/01/2023 | A_1 | aah |
01/01/2023 | A_1 | aa/i |
01/01/2023 | A_1 | aaj |
02/01/2023 | A_1 | aa/b |
02/01/2023 | A_1 | aa/c |
02/01/2023 | A_1 | aad |
02/01/2023 | A_1 | aae |
02/01/2023 | A_1 | aa/f |
02/01/2023 | A_1 | aag |
02/01/2023 | A_1 | aah |
02/01/2023 | A_1 | aa/i |
02/01/2023 | A_1 | aaj |
01/01/2023 | FN | a |
01/01/2023 | FN | b |
01/01/2023 | FN | c |
01/01/2023 | FN | d |
01/01/2023 | FN | e |
01/01/2023 | FN | g |
01/01/2023 | FN | h |
01/01/2023 | FN | i |
02/01/2023 | FN | a |
02/01/2023 | FN | b |
02/01/2023 | FN | c |
02/01/2023 | FN | d |
02/01/2023 | FN | e |
02/01/2023 | FN | g |
02/01/2023 | FN | h |
02/01/2023 | FN | i |
You may have to escape the slash with a backslash e.g. 01\/01\/2023 although this is not a quantifier, for that you are looking for + or * or {1} for example. Please check all the values you have in your tokens.