You can filter using two methods, index=index_name source=sourcetype
| regex _raw="DESCRIPTION=\".{5}(?:M|H)"
| table JOID,JOB_NAME,DESCRIPTION,JOB_GROUP,STATUS,LAST_START,LAST_END,NEXT_START,RUNTIME
| sort -time Or, index=index_name source=sourcetype
| rex "DESCRIPTION=\".{5}(?<sixth_char>.)"
| table JOID,JOB_NAME,sixth_char,DESCRIPTION,JOB_GROUP,STATUS,LAST_START,LAST_END,NEXT_START,RUNTIME
| search sixth_char IN ("H","M")
| sort -time
... View more