Hi
I dont know why my eval command doesnt return any resulys
`index`
| lookup tutu.csv HOSTNAME as host output SITE
| stats values(SITE) as Site, values(index) AS index BY host
| eval check=if(index="ai-toto*" ,"toto index only","All indexes")
| search check="toto index only"
| table host
If I delete the eval comamnd I have results
I have done a workaround like this:
| stats values(SITE) as Site, dc(index) AS index BY host
| where NOT index==4
It works but I would like to know why my original search doesnt works
`index`
| lookup tutu.csv HOSTNAME as host output SITE
| stats values(SITE) as Site, values(index) AS index BY host
| eval check=if(index="ai-toto*" ,"toto index only","All indexes")
| search check="toto index only"
| table host
this query's index
is multivalue.
so | eval check=if(index="ai-toto*" ,"toto index only","All indexes")
is not work.
`index`
| lookup tutu.csv HOSTNAME as host output SITE
| stats values(SITE) as Site, values(index) AS index BY host
| eval check=if(index="ai-toto*" ,"toto index only","All indexes")
| search check="toto index only"
| table host
this query's index
is multivalue.
so | eval check=if(index="ai-toto*" ,"toto index only","All indexes")
is not work.
try this:
`index` | lookup tutu.csv HOSTNAME as host output SITE | stats values(SITE) as Site, values(index) AS index BY host | mvexpand index | eval check=if(match(index,"ai-toto*") ,"toto index only","All indexes") | search check="toto index only" | dedup host | table host
thanks its ok