Folks, I'm trying to match a field (user) from a search to see if any previous notable events ES have been generated for that use and output any match.
Cannot seem to get any output
Tried the below:
index=*** sourcetype=*** category="alerttype"| rex field=fieldWithUserID "(?[^:]+$)" | search [ search notable
| fields user dest
| format "(" "(" "OR" ")" "OR" ")"]
I think you are using the subsearch incorrectly:
The [subsearch] finds the users and uses that list as an OR seperated filter in the main search:
index=notable [ index=YOURINDEX sourcetype=YOURSOURCETYPE category="alerttype"| rex field=fieldWithUserID "(?<user>[^:]+$)" | fields user | dedupe user ]
great thanks, got it to work using your search. 5*
I think you are using the subsearch incorrectly:
The [subsearch] finds the users and uses that list as an OR seperated filter in the main search:
index=notable [ index=YOURINDEX sourcetype=YOURSOURCETYPE category="alerttype"| rex field=fieldWithUserID "(?<user>[^:]+$)" | fields user | dedupe user ]