Our named searches are being audited. Named searches are those that have a specific User name in the actual search syntax. Those are audited and I would like to find a way to attach a ticket number to the search so a named search would be labeled by a ticket number.
Is there a way to do this on an inline search?
My only suggestion would be for you to stick an extraneous eval
command in the middle of the search, e.g., from:
sourcetype=mysourcetype userid=xyz | stats count by source_ip
to
sourcetype=mysourcetype userid=xyz | eval ticket_number="ABC1234567" | stats count by source_ip
My only suggestion would be for you to stick an extraneous eval
command in the middle of the search, e.g., from:
sourcetype=mysourcetype userid=xyz | stats count by source_ip
to
sourcetype=mysourcetype userid=xyz | eval ticket_number="ABC1234567" | stats count by source_ip
That's it! So simple! Thank you!