Thanks. Not working...
Here is a sample sources:
Here's my search:
index=main sourcetype=checklogpermissions RESOURCETYPE=file (RESOURCE!="du" AND RESOURCE!="cd") |fields RESOURCE |table RESOURCE | eval filedate=strftime(now(), "%Y%m%d*") |eval mySource="ORS_Node*PR." + file_date + ".log" |where match(RESOURCE,mySource)
Comes back with nothing. If I remove the where clause, it comes back with a bunch. I'd like to be able to search across all the source examples, using wildcards, rather than hard-coding anything.
You didn't tell me that the field in question is
RESOURCE. This is why you should ALWAYS post your search strings. I naturally assumed that you were using field
source. Try this:
index=main sourcetype=check_log_permissions RESOURCE_TYPE=file (RESOURCE!="du" AND RESOURCE!="cd") [|noop|stats count AS RESOURCE|eval RESOURCE=strftime(now(), "*%Y%m%d_*_*")]