Hi,
I have a lookup containing some admin users and I need to add some text like "ADS_" before the username to distinguish them from normal users. I tried:
index=myindex tag=authentication
| lookup Ads.csv Utenza AS username OUTPUT Gruppo
| fillnull value=NULL
| eval username=if(Gruppo="NULL",username, ADS_.username)
| eval action=if(match(details_message,"opened a Web Portal"),"success",action)
| search action=success dest_host!="- -"
| stats count by username
| sort count desc
what I'm missing?
Thanks in advance!
| eval username=if(Gruppo="NULL",username, "ADS_".username)
Hi @marco_massari11,
the eval statement isn't correct:
index=myindex tag=authentication
| lookup Ads.csv Utenza AS username OUTPUT Gruppo
| fillnull value=NULL
| eval username=if(Gruppo="NULL",username, "ADS_".username)
| eval action=if(match(details_message,"opened a Web Portal"),"success",action)
| search action=success dest_host!="- -"
| stats count by username
| sort count desc
Ciao.
Giuseppe