A log is parsed into below meta keys
aba = 'xxxx'
dda = 'yyyy'
I have blacklist of aba,dda pair
I need to alert if any log has aba=aba1 and dda=dda1
OR aba=aba2 and dda=dda2
I should not alert when aba=aba1 and dda=dda2
One solution i have in mind is as below which i am not sure works.
To create custom meta key which is created while log is parsed by SA
abadda = aba||'!'||dda
Hence i am looking for a way to create abadda (a custom meta key carved out of existing metakeys)
Alternative way to accomplish above alerting.
Uma Mahesh | 7068402149