Suppose I have a query like:
index=my_index stringA OR stringB OR stringC | table logentry, whatmatched
And for the "whatmatched" field, I would like to have the particular string against my raw data has matched, yielding an output like:
logentry | whatmatched
this is message with stringB | stringB
stringC comes here | stringC
Is it possible to extract this somehow?
try this
| eval whatmatched = case(like(_raw, "%string1%"), "string1", like(_raw, "%string2%"), "string2", like(_raw, "%string3%"), "string3")