(( host="vwp054" AND source="E:\\Apache\\apisit\\*")) | eval site = if(match(source,"E:\A.*"),1,0) | eval aba = if(source=="E:\\Apache\\apisit\\*",1,0)
I want "aba" to be one, or "site" to be one, but splunk gives me zero. I guess that probably I can't use *(wildcard) in string comparison or not even in match function. Can you help me specify the string comparison expression.
Try this:
| makeresults | eval source="E:\\Apache\\apisit\\*" | eval site = if (source like "E:\A%",1,0) | eval api = if(source like "E:\Apache\a%",1,0)