Hi @IZ88 , How are you doing ? I need a help from you. Could you please help me to generate a single query from these 3 separate queries ? The index is same in 1 & 2 queries. The source types of all 3 are different. Thank you. 1. index="abc_oracle" source=audit_19c sourcetype="audit" | eval "Database Modifications:" = "Modification on " + host, "Date and Time" = TIMESTAMP, "Type" = SQL_TEXT, "User" = DB_USER , "Source" = sourcetype | search "Database Modifications:"="Modification on *" NOT select | rex field=_raw "SQL_TEXT=\S(?P<Type>\W?......)\s" | rex field=_raw "DB_USER=(?P<UserName>..........)" | table "Date and Time", "Database Modifications:" ,"Type", "User", "Source" 2. index="abc_oracle" source=audit_row_19c sourcetype="audit" | eval "Database Modifications:" = "Modification on " + host, "Date and Time" = TIMESTAMP, "Type" = SQL_TEXT, "User" = DB_USER , "Source" = sourcetype | search "Database Modifications:"="Modification on *" NOT select | rex field=_raw "SQL_TEXT=\S(?P<Type>\W?......)\s" | rex field=_raw "DB_USER=(?P<UserName>..........)" | table "Date and Time", "Database Modifications:" ,"Type", "User", "Source" 3. index="abc_11g" source=oracle_11g sourcetype="audit" | eval "Database Modifications:" = "Modification on " + host, "Date and Time" = TIMESTAMP_qab, "Type" = SQL_TEXT, "User" = DB_USER , "Source" = sourcetype | search "Database Modifications:"="Modification on *" NOT select | rex field=_raw "SQL_TEXT=\S(?P<Type>\W?......)\s" | rex field=_raw "DB_USER=(?P<UserName>..........)" | table "Date and Time", "Database Modifications:" ,"Type", "User", "Source" Thank you
... View more