i wanna know how to display the result after specifying an if condition.
the sample search is like :
index=xyz | order="0000" | eval Order_status=if(order!=0,"found","not found") | .....
after this condition, if order=found, I need to display a table with few fields....please help me to solve this.
Hi Premkumarpalanichamy,
something like this works perfect for me:
index=_internal | head 1 | eval order="0000" | eval Order_status=if(order!="0","found","not found") | table Order_status order | where Order_status="found"
adapt it to your needs.
cheers, MuS