Hi
How can search something like this:
40: message.body.v10.timeLocalTransaction: [00*]
FYI: seems not support special char in search.
Thanks,
| makeresults | eval event="40: message.body.v10.timeLocalTransaction: [001]"
| regex event="40: message.body.v10.timeLocalTransaction: \[00.+\]"
Special characters need to be escaped
| makeresults | eval event="40: message.body.v10.timeLocalTransaction: [00*]"
| regex event="40: message.body.v10.timeLocalTransaction: \[00\*\]"
star is wild card not "*"
e.x
[001]
[000008]
[0032]
| makeresults | eval event="40: message.body.v10.timeLocalTransaction: [001]"
| regex event="40: message.body.v10.timeLocalTransaction: \[00.+\]"
It work but slow!
is it possible to do this faster? I mean tune spl command?
Thanks,
Where is it slow? Analyse the job inspector to see where processing is taking place, then look to see if you can modify the query to improve the performance. Sometimes, large amounts of data take a long time to process!