Hello,
I have a search woring which returns single IP addresses as source for certain events. As part of this I want to pass the source address into the eval function. I have eval working with "eval ip = "10.0.0.2" I am then passing this into a lookup table and everything is great but I want to automate this so that the results from source are automatically passed through eval IP and then matched on my lookup so that I can return additional information form the lookup.
However I can't get the eval function to use the results from the source field returned as per the search. I have tried the following:
eval IP = source
eval source as IP
I must be missing something can someone put me out my misery please?
Whenever you use eval
and you want to pass a field into it, you must have single tic's around the field value.
So if you wanted IP to be source, it would look like this
| eval IP='source'