Ahh..thanks, this was killing me. I was also having trouble with the eval statement checking an array value (kept erroring out), but seems like spath was the key there as well. This ended up workin...
See more...
Ahh..thanks, this was killing me. I was also having trouble with the eval statement checking an array value (kept erroring out), but seems like spath was the key there as well. This ended up working for me: index=someindex
| spath output=sentSubject "Item.Subject"
| spath output=receivedSubject "AffectedItems{}.Subject"
| eval subject = if(isnull(sentSubject),receivedSubject,sentSubject)
| table UserId,subject,Operation, _time