Hi i want to retrieve events that does not have "-" in the request url.
index=con_jira [| gentimes start=-1 | eval source="/opt/atlassian/current/logs/access_log." + strftime(now(), "%F") | return source] "GET /browse" | eval headers=split(_raw," ") | eval method=mvindex(headers,5) |eval request=mvindex(headers,6) | where request!="*-" | table request
sample Result:
/browse/EPS -----> correct result
/browse/ISPTEXAS-27534 ----> wrong result
... View more