I need to extract the Activity Score and Application UXI Average but only when the Application Name is a certain name.
It's a weird one for me because of the way data comes in. As you can see each event has multiple application names, activity scores, uxi averages and timeframes. So even when I specify for a certain app in a search, since the app name is in an event, I get the whole event which includes all the other apps and metrics.
I hope what I'm explaining is clear and any help would be appreciated.
| spath value{} output=value
| mvexpand value
| spath input=value
| where APPLICATION_NAME="certain app"
| spath value{} output=value
| mvexpand value
| spath input=value
| where APPLICATION_NAME="certain app"
Works perfectly, thank you!