I have a following query:
index=main source=mylogsource.log "Response Message:*" "234998102"
| ifnoresults ---> (eval message | show message), if there are results --> continue applying the next commands
| eval number = 234998102
| rex field=_raw "(?:<balance couponType=\"Customer\">)(?P<customerCoupons>\d+)(?:</balance>)"
| rex field=_raw "(?:<balance couponType=\"Companion\">)(?P<companionCoupons>\d+)(?:</balance>)"
| rex field=_raw "(?:<balance couponType=\"Both\">)(?P<bothCoupons>\d+)(?:</balance>)"
| table number, trkid, customerCoupons, companionCoupons, bothCoupons
My idea is show a message if the base search doesn't have results or continue with the commands pipe if there are results.
It is possible achieve this?
... View more