Hey Splunkers,
I have the following search but it is not working as expected. What I am trying to achieve is if one of the conditions matches I will table out some fields.
condition 1 : if user_action="Update*"
OR
Condition 2: within each 5 min bucket, if any user has access more than 400 destination in the same index, index1
but it doesn't work. How can I check both condition on the same search?
Thanks in advanced!
index=index1
``` condition 1 ```
( user_action="Update*" )
OR
``` condition 2 ```
(
[search index=index1 NOT user IN ("system*", "nobody*")
| bin _time span=5m
| stats values(dest) count by _time, user
| where count > 400 ]
)
| table _time, user, dest
... View more