Hi Team,
Below is my query:
index= "abc*" sourcetype=600000304_gg_abs_ipc1 OR sourcetype=600000304_gg_abs_ipc2 "Message successfully sent to Cornerstone" source!="/var/log/messages"
I am getting result of " sourcetype=600000304_gg_abs_ipc1
I am not getting result of 600000304_gg_abs_ipc2
I need result of both sourcetype in one frame.
Can someone help
Hi @aditsss,
are you sure that tha additional conditions ("Message successfully sent to Cornerstone" source!="/var/log/messages") are true for both the sourcetypes?, maybe you have to use parenthesis to separate conditions.
Ciao.
Giuseppe
yes its true for both
Hi @aditsss ,
did you tried something like this:
index= "abc*" (sourcetype=600000304_gg_abs_ipc1 OR sourcetype=600000304_gg_abs_ipc2) "Message successfully sent to Cornerstone" source!="/var/log/messages"
?
Ciao.
Giuseppe