...UTPUTNEW <lookup-destfield1> AS <local-destfield1>, <lookup-destfield2> AS <local-destfield2>
Here's my understanding of it, and hopefully someone can fill in the gaps or c...
Hello Guys,
I am getting confused about this below query, can anyone help me to understand it.
Actually in the search query there is "AND" commands with the same Field name, I am n...
...vents for SEARCH-2. I suspect something about the way the 'saved search' is utilized , I quite don't understand the difference in result. Any idea , why ?
...cenario I cannot explain and wanted to understand further. While testing I created this search: | makeresults
| eval value=0, category="test", _time=strftime(now(), "%H")
| a...
I think I have a conceptual problem understanding these two commands but in my mind you'd build a model with fit and somehow use that model to forecast (predict) future events right? But for t...
Trying to understand how this SEDCMD works so I can modify it for something else. It works in props.conf but I can't seem to get it to work in SPL.
Here is the event log:
Jul 1 19:58:45 f...
I'm trying to put into practice what I saw in Michael Wilde's Regex video with regards to making rex searches persistent. I must be missing something because I'm not getting the results I'm after.
...
Hi All, I have the below search. I am being told it appends results to a lookup table called user_ids.
index=ad earliest=-15d
|stats latest(_time) as _time, latest(prof...
Hi, I would like to know if there is the possibility to automatically trigger a playbook when there is a change in the status of a container (e.g. when it becomes "Closed")? Thank you in advance!
...nput to choose appropriate index for the base search. However it looks like it picks up just prod, and not returning results for ppe.
Can someone please help me to understand what is wrong with my c...