Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Set multiple tokens using "condition match"

$
0
0
To set tokens, I have several "condition match" in a search but, if more than one condition is matched, only the first one seems to work. To simplify my use case:index=_internal | stats count by host | table host, count@dnow1t1t2 What I expect is that both tokens will be set (both result.host and result.count exist and have a value). However, only "showtab1" is set. To my surprise, if I swap the conditions order: [...] t2t1 [...] Now, "showtab2" is set (and "showtab1" is unset...) What I'm missing here?

Viewing all articles
Browse latest Browse all 47296

Trending Articles