Reporting

Help with filtering on base search with If query

POR160893
Builder

Hey,

I have a big base search  and I want to add a condition in the search that would remove/ filter out Asset_State if either Development or "Pre-Production" ONLY IF     Asset_Environment!="PKI Offline" Status="2.

At the moment, this is the line in the query I have for this:
.......| if(Asset_Environment!="PKI Offline" Status="2, search NOT (Asset_State!="Development" OR Asset_State!="Pre-Production") |....


Syntactically, I know this is incorrect .... can someone please help???


Many thanks as always!!!

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...