I am getting this in output of the search index=* host="216.167.15.70" and getting dest_port field value as "ssh" , I want to convert this field value to 22,please help me on this...
use replace like
..|replace ssh with "22" in dest_port
View solution in original post
my csv file is dest_port,value ssh,22
and I am writing this csv file in search head