You need the
where command. This is one of the big differences between using
search vswhere` for subsequently filtering results.
Just add this to your search:
| where cs_bytes > sc_bytes
search the right hand side of any operator (ie =, >, <) is always assumed to be a literal value (whether or not it's in quotes) but in
where unquoted strings on the right hand side are interpreted as the values of that named field.
The other huge difference of course, is that in
where you can use any eval functions (ie any of the long list of functions you would more typically see in the
So to take a simple example, you could filter to only the rows where
cs_bytes is greater than BOTH
| where cs_bytes > max(sc_bytes,some_other_bytes)