I would like to match/pick only the event which contains "ccexpire".
sample event :-
09/Dec/2021 23:52:39,Query,"SELECT ccexpire FROM creditcard WHERE userid = 624",7
There are many events which has ccexpire would like to extract the events which has ccexpire.
Thank you.. But how do i pick those events and map it to some field as i need to get the count.
Hi @Borntowin
you can try using
| stats count
Hi @Borntowin
one way you can do it search for keyword ccexpire , to filter out events
<your query> | search "*ccexpire *"