I had this search working and now it seems to have stopped gives an error. Thoughts?
Search:
index=symantec sourcetype=file Host_Name=[search index=dhcp "*ip address*" "DHCPACK" AND "RENEW"| sort by _time desc | rex "\((?.*?)\)"| dedup Hostname | table Hostname | return $Hostname] | dedup user | eval time=strftime(_time, "%m/%d/%Y %H:%M:%S") | table time,Host_Name,user,_raw
Error:
Error in 'search' command: Unable to parse the search: Comparator '=' is missing a term on the right hand side.
... View more