I have a field called rules_tripped
It returns the results like this
rules_tripped="5237260000001713515:Item Sku Fraud & Chargeback Percentage 0:0"
Rule ID : Rule Name : Rule Score
I want to only search for rules that have a rule score of > 800
Is that possible to split the query and search for only rules with a rule score of > 800?
Try this
| eval rules_score=mvindex(split(rules_tripped,":"),2)
| where rules_score > 800
That worked perfectly, thank you!!!
Try this
| eval rules_score=mvindex(split(rules_tripped,":"),2)
| where rules_score > 800