Hi
How to write spl search query by adding multiple field in single search
Field 1 - contain data like authorization " Write or Read "
Field 2 - contain user id details like " @abc.com , user1, user 2,
Question
How to write a spl query
Index =testing ("write" AND " @abc.com" )
spl query to add multiple filed which contain " write " AND "@abc.com" when these condition satisfied an alert has to been sent
May I misunderstand your question, but it's simple:
index= testing field1="write" field2="*@abc.com"
|table field1, field2, ....
if "@abc.com" is a user name and not a domain (as I assume) you do not need to put the wildcard (*) before. If you put it, it will result in every user with @abc.com. Like, user1@abc.com, user2@abc.com...
alternative:
index=testing | stats count by field1 field2 | search field1="write" AND field2"*@abc.com"
Regards,
Hi please
find the below image
Please paste the text (not an image) of the search into code block (otherwise, it is too small to be read easily)
Please share some of the events whish are being returned incorrectly (anonymised appropriately)
Try
Index=testing ("write" AND " @abc.com" )
What results do you get?