I get a minus error if the search if looks like this:
index=my_index sourcetype=my_sourcetype
| eval my_field = if (isnotnull(my_field), my_field_2, my.field-2)
I can work around it my changing the SPL to
index=my_index sourcetype=my_sourcetype
| rename my.field-1 AS my_field_1
| eval my_field = if (isnotnull(my_field), my_field_2, my.field-1)
I tried quoting, but the value of my_field became "my.field-2" and not the value. Is there a way of escaping my.field-1 in the "if" so it reads the contents or will I have to use a rename?
TIA,
Joe
try single quote around field name like 'my.field-2'
I thought I had tried that, but it looks like I didn't since it worked.
glad it worked 😉