I would like to return all messages that contains tag 6410. Currently the below will return all messages even if they do not contain tag 6410
index=gmrt_ett sourcetype=pubhub_emea TracingIncomingMessage "ET_OMS" | search "6401=POV"
| extract pairdelim=";" kvdelim="\=" clean_keys=false
| dedup _raw
| searcg 6410=(?.*)
| table 11,6410
This will do it if anyone needs, simplere than I thought
index=gmrt_ett sourcetype=pubhub_emea TracingIncomingMessage "ET_OMS" | search "6401=POV"
| extract pairdelim=";" kvdelim="\=" clean_keys=false
| dedup _raw
| search 6410=*
| table 11,6410