I have two logs below, log a is throughout the environment and would be shown for all users. log b is limited to specific users. I only need times for users in log b.
log a: There is a file has been received with the name test2.txt
lob b: The file has been found at the second destination C://user/test2.txt
I am trying to write a query that captures the time between log a and log b without doing a subsearch, so far I have
index=a, env=a, account=a ("There is a file" OR "The file has been found")|field filename from log b | field filename2| eval Endtime = _time | ****Here is where I am lost, I was hoping to use if/match/like/eval to see to capture the start time where log b filename can be found in log a. I have this so far******
| eval Starttime = if(match(filename,"There is%".filename2."%"),_time,0)
I am not getting any 1s, just 0s. I am pretty sure this is the problem "There is%".filename2."%", how do I correct it.
... View more