Is there a method to do "AND" while writing regex instead of "OR" . As when i write a reg and add to regex _raw="expression". Since using "|" its matching a lot of similar logs .
It would help to see some example data and your current query. However, you may accomplish your goal using where instead of regex.
... | where (match(_raw, "expression") AND match(_raw, "other expression")
It would help to see some example data and your current query. However, you may accomplish your goal using where instead of regex.
... | where (match(_raw, "expression") AND match(_raw, "other expression")