I have multiple events where in each individual event, I'm extracting multiple fields using regex. Essentially it looks like this where each BU is a separate field I'm extracting from the event:
BU1 - 84.5xx.x
I want to compare all extracted fields from each individual event and display only the the highest number as another field lets say largest_BU. Is there any way to do this?
Thank you in advance.
Yes, like this:
...| eval largest_BU=0 | foreach BU* [ eval largest_BU=max(largest_BU, <<FIELD>>) ]
View solution in original post
Thank you, and as a side note it also worked when i set my rex to search for that specific pattern with a max_match=0, then i just use eval max