index=mysql sourcetype=audit_log earliest=1 | rex field=source "\/home\/mysqld\/(?<Database1>.*)\/audit\/" | rex field=source "\/mydata\/log\/(?<Database2>.*)\/audit\/" | eval Database...
See more...
index=mysql sourcetype=audit_log earliest=1 | rex field=source "\/home\/mysqld\/(?<Database1>.*)\/audit\/" | rex field=source "\/mydata\/log\/(?<Database2>.*)\/audit\/" | eval Database = coalesce(Database1,Database2) | fields - Database1,Database2 | rex field=USER "(?<USER>[^\[]+)" | rex mode=sed field=HOST "s/\.[a-z].*$//g" | eval TIMESTAMP=strptime(TIMESTAMP, "%Y-%m-%dT%H:%M:%S UTC") | where TIMESTAMP > now()-3600*24*90 | eval TIMESTAMP=strftime(TIMESTAMP, "%Y-%m-%d") | eval COMMAND_CLASS=if(isnull(COMMAND_CLASS) OR COMMAND_CLASS="", "NA", COMMAND_CLASS) | eval HOST=if(isnull(HOST) OR HOST="", "NA", HOST) | eval IP=if(isnull(IP) OR IP="", "NA", IP) | eval Action=if(isnull(NAME) OR NAME="", "NA", NAME) | eval STATUS=if(isnull(STATUS) OR STATUS="", "NA", STATUS) | eval Query=if(isnull(SQLTEXT) OR SQLTEXT="", "NA", SQLTEXT) | eval USER=if(isnull(USER) OR USER="", "NA", USER) | stats count as Events by Database USER HOST IP COMMAND_CLASS Action STATUS Query TIMESTAMP | lookup mysql_databases.csv DATABASE as Database OUTPUT APP_NAME | eval APP_NAME=if(isnull(APP_NAME) OR APP_NAME="", "NA", APP_NAME)
and hence getting no output in search and reporting tab