Hi,
I have a field called "Applications". I want to populate this field from events based on a patterns.
date: xxxxxx
Based on the above example, I want to check for date:xxxxx followed by "foobar" and populate the field "Applications" with "MyApplcationName".
How can I go about doing this?
Thank you,
Chris
You could do this:
yoursearchhere
| eval Applications=if(match(_raw,"date:xxxxx.*foobar"),"MyApplcationName",Applications)
You could even create a calculated field if you want this to be done automatically for every search.
You could do this:
yoursearchhere
| eval Applications=if(match(_raw,"date:xxxxx.*foobar"),"MyApplcationName",Applications)
You could even create a calculated field if you want this to be done automatically for every search.
Perfect. Calculated fields is where I needed to be pointed to. Got it working.
Thank you!
Chris