In my search result i am getting AD & Login locations.
Now I want to filter result, if both AD and Login locations are same.
Please help me with splunk query
@soutamo @saravanan90 @thambisetty @ITWhisperer @gcusello @bowesmana @to4kawa
Hi @alexspunkshell,
Please try this;
| rex field=login_location "(?<logloc>\w\w$)"
| rex field=AD_location "(?<adloc>\w\w$)"
| fillnull value="-" adloc logloc
| where logloc=adloc
Hi @alexspunkshell,
Please try this;
| rex field=login_location "(?<logloc>\w\w$)"
| rex field=AD_location "(?<adloc>\w\w$)"
| fillnull value="-" adloc logloc
| where logloc=adloc
Assuming last two letters are the location you are interested in
| rex field=login_location "(?<logloc>\w\w$)"
| rex field=AD_location "(?<adloc>\w\w$)"
| where logloc=adloc
@ITWhisperer This query also filters if logon & Ad location is empty.
But I need to captured in result if those fields are empty. Could you plz help here.