Hi Guys,
Good Day!
Just want to ask on how can I remove YYYYMMDD HH24:MI:SS") event on my search table. Here is my search and the result.
index=nf_index source=/appl/in_house/batch/AS*
| multikv
| stats count by "ACCESS CODE"
index=nf_index source=/appl/in_house/batch/AS*
NOT "ACCESS CODE"="YYYYMMDD*"
| multikv
| stats count by "ACCESS CODE"
Or you could fix your data onboarding and don't index those events, because it seems these values are the result of something that is parsed incorrectly.
index=nf_index source=/appl/in_house/batch/AS*
NOT "ACCESS CODE"="YYYYMMDD*"
| multikv
| stats count by "ACCESS CODE"
Or you could fix your data onboarding and don't index those events, because it seems these values are the result of something that is parsed incorrectly.
You could try the simple boolean check of isint()
index=nf_index source=/appl/in_house/batch/AS*
| multikv
| stats count by "ACCESS CODE"
| where isint("ACCESS CODE")