Greetings.
I am using multiple sourcetypes in a query that I am working with. If you open a search using something like this
sourcetype=SOURCE1 OR sourcetype=SOURCE2 OR sourcetype=SOURCE3
Playing around, if I try to filter anything with SOURCE1's events, all of the events from SOURCE2 and SOURCE3 get eliminated as well. For example (where AS_AS_Call_Type is an event field found only in SOURCE1):
sourcetype=SOURCE1 or sourcetype=SOURCE2 OR sourcetype=SOURCE3 AS_AS_Call_Type=network
Only events of SOURCE1 get returned. What I want is to keep all of the events from SOURCE2 and SOURCE3, along with the filtered events of SOURCE1.
How can I do this?
Hi!
Perhaps what you're trying to do is:
(sourcetype=SOURCE1 AS_AS_Call_Type=network) OR sourcetype=SOURCE2 OR sourcetype=SOURCE3
This will match events with "sourcetype=SOURCE1 AND AS_AS_Call_Type=network", as well as the other two sourcetypes.
Does that make sense?
Hi!
Perhaps what you're trying to do is:
(sourcetype=SOURCE1 AS_AS_Call_Type=network) OR sourcetype=SOURCE2 OR sourcetype=SOURCE3
This will match events with "sourcetype=SOURCE1 AND AS_AS_Call_Type=network", as well as the other two sourcetypes.
Does that make sense?
Makes sense! The only command that seems not to be working is isnotnull(field) but I can do without that for now. Thank you!