Hi Team,
I have a situation where I need to base a field value in the normal search query on 'true' or 'false' based on another field
example :
index=xxx host=xxx sourcetype=xxx productcode="RE" countryid="74321"
what I need is that if the field 'countryid' is equal to '74321' the other field 'foundincache' set to only 'false' if not it should be set to 'true'
I tried something like this but it doesnt take the value from 'inscache'. I mean inscache is not working as a variable
index=xxx host=xxx sourcetype=xxx productcode="RE" countryid="74321"
| eval countryid="70207"
| eval inscache=if(countryid=="70207","false","true")
| search foundincache=inscache
| stats count by foundincache
Is there a way to do it I tried google search etc but cant find this anywhere
Many thanks in adavance
Nishant
Search doesn't work with variables on the right hand side of evaluations, use the where command instead
| where foundincache==inscache
Search doesn't work with variables on the right hand side of evaluations, use the where command instead
| where foundincache==inscache
OMG, this is truly amazing, incredible, superb.
I had no idea it be that simple.
thanks thanks thanks and thanks a lot @ITWhisperer