hi
I use the search below
| inputlookup lookup_xx where TYPE="Ind"
| search DOMAIN=I OR DOMAIN=B OR DOMAIN=W
| rename HOSTNAME as host
| table host TYPE DOMAIN
Instead using | search, I would like to include this in my Where condition but it doesnt works
| inputlookup lookup_xx where TYPE="Ind" AND (DOMAIN=I OR DOMAIN=B OR DOMAIN=W)
| rename HOSTNAME as host
| table host TYPE DOMAIN
how to do this please?
and for performances is it better to use Where or search?
[| inputlookup lookup_xx
| search TYPE="Ind" AND (DOMAIN=I DOMAIN=B OR DOMAIN=W)
| rename HOSTNAME as host ] `w`
And why I can do
[| inputlookup lookup_xx
| where TYPE="Ind" OR (DOMAIN=I OR DOMAIN=B OR DOMAIN=W)
But not
[| inputlookup lookup_xx
| where TYPE="Ind" AND (DOMAIN=I OR DOMAIN=B OR DOMAIN=W)
Thanks for your help
Hi @jip31
Have you tried without using boolean operators outside parenthesis, like this?
| inputlookup lookup_xx where TYPE="Ind" (DOMAIN=I OR DOMAIN=B OR DOMAIN=W)
Hi @jip31
Have you tried without using boolean operators outside parenthesis, like this?
| inputlookup lookup_xx where TYPE="Ind" (DOMAIN=I OR DOMAIN=B OR DOMAIN=W)
perfect thanks