- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It's a simple search query. It needs to find events containing a file name which will change every month.
The eval command should return YYmm* (1412*).
This query works
The eval field signatureVersionCriteria has been replaced -hard coded- with the value it should hold.
The field values shown in a table do indeed display "1412*" for the signatureVersionCriteria field.
index=xxx_app_sep | eval signatureVersionCriteria = strftime(now(), "%y%m") + "*" | search signature_version="1412*"| table signature_version, signatureVersionCriteria
This query does not work
It returns nothing.
index=xxx_app_sep | eval signatureVersionCriteria = strftime(now(), "%y%m") + "*" | search signature_version = signatureVersionCriteria | table signature_version, signatureVersionCriteria
Went through quite a lots of posts, similar to this, but could not figure it out.
Many thanks.
D
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Try the following:
index=xxx_app_sep | eval signatureVersionCriteria = strftime(now(), "%y%m") | where like(signature_version,signatureVersionCriteria."%") | table signature_version, signatureVersionCriteria
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Try the following:
index=xxx_app_sep | eval signatureVersionCriteria = strftime(now(), "%y%m") | where like(signature_version,signatureVersionCriteria."%") | table signature_version, signatureVersionCriteria
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello! Many thanks it does indeed work.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi David,
If Aleksander's answer has solved your problem, please accept the answr by clicking on the tick-mark+Accept button below the answer. This will help other users with similar problem to identify the correct solution and you both will get points.
