index="abc" `abc_sourcetype` host="$Database$" | eval sourcetype=lower(sourcetype) | rex mode=sed field=sourcetype "s/oracle:audit:(.*)\d\d/\1/g" | rex mode=sed field=USERHOST "s/\..*//g" | eval ACTION_NAME=if(isnull(ACTION_NAME) OR ACTION_NAME="", "TBD", upper(ACTION_NAME)) | eval DBUSERNAME=if(isnull(DBUSERNAME) OR DBUSERNAME="" OR DBUSERNAME="TBD", "TBD", upper(DBUSERNAME)) | eval OS_USERNAME=if(isnull(OS_USERNAME) OR OS_USERNAME="" OR OS_USERNAME="TBD", "TBD", lower(OS_USERNAME)) | eval RETURN_CODE=if(isnull(RETURN_CODE) OR RETURN_CODE="", 0, RETURN_CODE) | eval OBJECT_NAME=if(isnull(OBJECT_NAME) OR OBJECT_NAME="", "TBD", upper(OBJECT_NAME)) | eval USERHOST=if(isnull(USERHOST) OR USERHOST="", "TBD", lower(USERHOST)) | eval TERMINAL=if(isnull(TERMINAL) OR TERMINAL="" OR TERMINAL="TBD", "TBD", upper(TERMINAL)) | eval query=if(isnull(query) OR query="", "TBD", lower(query)) | stats dc(time) as Events, latest(time) as LastSeen, earliest(time) as FirstSeen by Database, sourcetype, ACTION_NAME, DBUSERNAME, OS_USERNAME, USERHOST,OBJECT_NAME, RETURN_CODE, query, TERMINAL | convert ctime(*Seen) timeformat="%m-%d-%Y %H:%M:%S" here abc_sourcetype is macros so this search is working fine when sourcetype is in format oracle:audit:json12/11 but failing to load data for oracle:audit:json
... View more