Hi,
I want the "test" field to return a value of 1 for all events with the word "lookup" regardless of case.
index=idm-prdidx "Intuit.consumer.mintiusgrant.grantjob"
| eval test=if(like(api,"*lookup*"),1,0)
| table api test
Try this
index=idm-prdidx "Intuit.consumer.mintiusgrant.grantjob"
| eval test=if(match(api,"(?i)lookup"),1,0)
| table api test
Try this
index=idm-prdidx "Intuit.consumer.mintiusgrant.grantjob"
| eval test=if(match(api,"(?i)lookup"),1,0)
| table api test
Additionally if I wanted to have the wildcard only at the end of the word and still ignore case sensitivity, how I would I do that?
lookup*
Thanks!
That works! Thanks!!